« Volver al listado

CVE-2013-7039

Estado: ModificadaMedia (5.1)—

Stack-based buffer overflow in the MHD_digest_auth_check function in libmicrohttpd before 0.9.32, when MHD_OPTION_CONNECTION_MEMORY_LIMIT is set to a large value, allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long URI in an authentication header.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2013-7039",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5.1,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:H/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "HIGH",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 4.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2013-12-13T18:55:05.787",
  "references": [
    {
      "url": "http://secunia.com/advisories/55903",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://security.gentoo.org/glsa/glsa-201402-01.xml",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2013/12/09/11",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/64138",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://bugs.gentoo.org/show_bug.cgi?id=493450",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1039390",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://gnunet.org/svn/libmicrohttpd/ChangeLog",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/55903",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://security.gentoo.org/glsa/glsa-201402-01.xml",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2013/12/09/11",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/64138",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bugs.gentoo.org/show_bug.cgi?id=493450",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1039390",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://gnunet.org/svn/libmicrohttpd/ChangeLog",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-119"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Stack-based buffer overflow in the MHD_digest_auth_check function in libmicrohttpd before 0.9.32, when MHD_OPTION_CONNECTION_MEMORY_LIMIT is set to a large value, allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long URI in an authentication header."
    },
    {
      "lang": "es",
      "value": "Desbordamiento de búfer basado en pila en la función MHD_digest_auth_check en libmicrohttpd anterior a  0.9.32, cuando MHD_OPTION_CONNECTION_MEMORY_LIMIT se establece en un valor grande, lo que permite a atacantes remotos provocar una denegación de servicio (caída) o posibilitar  ejecutar código arbitrario a través de una  URI muy larga en  una cabecera de autenticación"
    }
  ],
  "lastModified": "2026-06-17T00:01:19.480",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:gnu:libmicrohttpd:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CB3F576D-E209-4442-84A0-F5720C0670B9",
              "versionEndIncluding": "0.9.31"
            },
            {
              "criteria": "cpe:2.3:a:gnu:libmicrohttpd:0.9.16:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "79204833-B005-4AEA-86FF-51DCC291C68D"
            },
            {
              "criteria": "cpe:2.3:a:gnu:libmicrohttpd:0.9.17:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6946AFC5-A1ED-4804-B0D5-FD954D299EDF"
            },
            {
              "criteria": "cpe:2.3:a:gnu:libmicrohttpd:0.9.18:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D0899B1B-7E70-41A5-B73E-BA1DBA2320C0"
            },
            {
              "criteria": "cpe:2.3:a:gnu:libmicrohttpd:0.9.19:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3BA9A39A-8223-495B-9A8E-653221E679A5"
            },
            {
              "criteria": "cpe:2.3:a:gnu:libmicrohttpd:0.9.20:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2288EFBB-0EAC-464A-90C0-890D4493A9B0"
            },
            {
              "criteria": "cpe:2.3:a:gnu:libmicrohttpd:0.9.21:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2893E9E6-986B-422F-BBE6-CD6B07A50B9D"
            },
            {
              "criteria": "cpe:2.3:a:gnu:libmicrohttpd:0.9.22:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AE6F1BC7-9ED0-4654-9C44-325DCEEF83AF"
            },
            {
              "criteria": "cpe:2.3:a:gnu:libmicrohttpd:0.9.23:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "89AE4C2E-74F1-4ECA-A45D-6F4C5E3BA652"
            },
            {
              "criteria": "cpe:2.3:a:gnu:libmicrohttpd:0.9.24:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "63A81F22-4EA6-4316-AE28-622249DC2501"
            },
            {
              "criteria": "cpe:2.3:a:gnu:libmicrohttpd:0.9.25:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EACB49FA-01C7-468E-A008-9E1B0CFCDF03"
            },
            {
              "criteria": "cpe:2.3:a:gnu:libmicrohttpd:0.9.26:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A3DD84B3-E569-4F0D-85AE-5E503C3974A9"
            },
            {
              "criteria": "cpe:2.3:a:gnu:libmicrohttpd:0.9.27:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "26F1581D-19AC-4D63-AEC4-EFBB591C8C34"
            },
            {
              "criteria": "cpe:2.3:a:gnu:libmicrohttpd:0.9.28:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EB70D1A6-65E1-49E0-88C0-8D57B1EF09C7"
            },
            {
              "criteria": "cpe:2.3:a:gnu:libmicrohttpd:0.9.29:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "362BC925-46F3-40B5-A430-C6766FA8999B"
            },
            {
              "criteria": "cpe:2.3:a:gnu:libmicrohttpd:0.9.30:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "33116DFB-667F-4494-970F-DF713AEC9466"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}