← Back

CVE-2013-4550

nvd nist
Published: Dec 24, 2013Modified: Apr 29, 2026

JSON object

Loading...
5.1
Vector
AV:N/AC:H/Au:N/C:P/I:P/A:P
Exploitability: 4.9 / Impact: 6.4
Source: NVD

Description

Bip before 0.8.9, when running as a daemon, writes SSL handshake errors to an unexpected file descriptor that was previously associated with stderr before stderr has been closed, which allows remote attackers to write to other sockets and have an unspecified impact via a failed SSL handshake, a different vulnerability than CVE-2011-5268. NOTE: some sources originally mapped this CVE to two different types of issues; this CVE has since been SPLIT, producing CVE-2011-5268.

Affected (14)

1 product
Fedora
1 product
Bip
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 18
Version 19
Version 20
Configuration B
11 vulnerable
Vulnerable SoftwareAffected Versions
Duckcorp
Up to 0.8.8
Version 0.8.0
Version 0.8.0 rc0
Version 0.8.0 rc1
Version 0.8.1
Version 0.8.2
Version 0.8.3
Version 0.8.4
Version 0.8.5
Version 0.8.6
Version 0.8.7

Related CWEs

Timeline

No history available yet.