Format string error in RRDtool - CVE-2013-2131
Published: January 4, 2015 / Updated: August 9, 2020
Vulnerability identifier: #VU40973
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2013-2131
CWE-ID: CWE-134
Exploitation vector: Remote access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform service disruption.
Format string vulnerability in the rrdtool module 1.4.7 for Python, as used in Zenoss, allows context-dependent attackers to cause a denial of service (crash) via format string specifiers to the rrdtool.graph function.
Affected software
RRDtool
Fedora
rrdtool
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)
Fedora
rrdtool
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)
How to mitigate CVE-2013-2131
Install update from vendor's website.
rrdtool - update to 1.2.27-4.el5
Dell EMC Unity VSA Operating Environment (OE) - update to 5.0.0.0.5.116
Dell EMC Unity Operating Environment (OE) - update to 5.0.0.0.5.116
Dell EMC Unity VSA Operating Environment (OE) - update to 5.0.0.0.5.116
Dell EMC Unity Operating Environment (OE) - update to 5.0.0.0.5.116
Links to Public Exploits and PoC-codes
External References
- http://www.openwall.com/lists/oss-security/2013/04/18/5
- http://www.openwall.com/lists/oss-security/2013/05/19/5
- http://www.openwall.com/lists/oss-security/2013/05/31/2
- https://bugzilla.redhat.com/show_bug.cgi?id=969296
- https://github.com/oetiker/rrdtool-1.x/issues/396
- https://github.com/oetiker/rrdtool-1.x/pull/397