Input validation error in Links - CVE-2013-6050
Published: December 7, 2013 / Updated: August 4, 2020
Vulnerability identifier: #VU33854
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2013-6050
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform service disruption.
Integer overflow in Links before 2.8 allows remote attackers to cause a denial of service (crash) via crafted HTML tables.
Affected software
Links
Gentoo Linux
Fedora
links (Alpine package)
bind (Alpine package)
links
Gentoo Linux
Fedora
links (Alpine package)
bind (Alpine package)
links
How to mitigate CVE-2013-6050
Install update from vendor's website.
links (Alpine package) - update to 2.8-r0
bind (Alpine package) - update to 9.9.4_p2-r0
links - update to 2.8-4.el6
bind (Alpine package) - update to 9.9.4_p2-r0
links - update to 2.8-4.el6