Vulnerability Description
Use-after-free vulnerability in UnrealIRCd 3.2.10 before 3.2.10.2 allows remote attackers to cause a denial of service (crash) via unspecified vectors. NOTE: this identifier was SPLIT per ADT2 due to different vulnerability types. CVE-2013-7384 was assigned for the NULL pointer dereference.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Unrealircd | Unrealircd | 3.2.10 |
Related Weaknesses (CWE)
References
- http://forums.unrealircd.com/viewtopic.php?f=2&t=8221Vendor Advisory
- http://seclists.org/oss-sec/2013/q4/379
- http://seclists.org/oss-sec/2013/q4/383
- http://www.unrealircd.com/txt/unreal3_2_10_2_release_notes.txt
- http://forums.unrealircd.com/viewtopic.php?f=2&t=8221Vendor Advisory
- http://seclists.org/oss-sec/2013/q4/379
- http://seclists.org/oss-sec/2013/q4/383
- http://www.unrealircd.com/txt/unreal3_2_10_2_release_notes.txt
FAQ
What is CVE-2013-6413?
CVE-2013-6413 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Use-after-free vulnerability in UnrealIRCd 3.2.10 before 3.2.10.2 allows remote attackers to cause a denial of service (crash) via unspecified vectors. NOTE: this identifier was SPLIT per ADT2 due to...
How severe is CVE-2013-6413?
CVE-2013-6413 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2013-6413?
Check the references section above for vendor advisories and patch information. Affected products include: Unrealircd Unrealircd.