CVE-2013-4550

Bip before 0.8.9, when running as a daemon, writes SSL handshake errors to an unexpected file descriptor that was previously associated with stderr before stderr has been closed, which allows remote attackers to write to other sockets and have an unspecified impact via a failed SSL handshake, a different vulnerability than CVE-2011-5268. NOTE: some sources originally mapped this CVE to two different types of issues; this CVE has since been SPLIT, producing CVE-2011-5268.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.1 UNKNOWN
NETWORK
HIGH
AV:N/AC:H/Au:N/C:P/I:P/A:P
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 76%
VendorProductVersion
duckcorpbip
𝑥
≤ 0.8.8
duckcorpbip
0.8.0
duckcorpbip
0.8.0:rc0
duckcorpbip
0.8.0:rc1
duckcorpbip
0.8.1
duckcorpbip
0.8.2
duckcorpbip
0.8.3
duckcorpbip
0.8.4
duckcorpbip
0.8.5
duckcorpbip
0.8.6
duckcorpbip
0.8.7
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
bip
bullseye
0.9.0~rc4-1
fixed
wheezy
no-dsa
squeeze
no-dsa
bookworm
0.9.3-1
fixed
sid
0.9.3-1.1
fixed
trixie
0.9.3-1.1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
bip
saucy
Fixed 0.8.8-2ubuntu1.1
released
raring
Fixed 0.8.8-2ubuntu0.13.04.1
released
quantal
Fixed 0.8.8-2ubuntu0.12.10.1
released
precise
Fixed 0.8.8-1ubuntu0.3
released
lucid
ignored
Common Weakness Enumeration