Format string error in RRDtool - CVE-2013-2131

 

Format string error in RRDtool - CVE-2013-2131

Published: January 4, 2015 / Updated: August 9, 2020


Vulnerability identifier: #VU40973
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2013-2131
CWE-ID: CWE-134
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform service disruption.

Format string vulnerability in the rrdtool module 1.4.7 for Python, as used in Zenoss, allows context-dependent attackers to cause a denial of service (crash) via format string specifiers to the rrdtool.graph function.


Affected software

RRDtool
Fedora
rrdtool
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)

How to mitigate CVE-2013-2131

Install update from vendor's website.

rrdtool - update to 1.2.27-4.el5
Dell EMC Unity VSA Operating Environment (OE) - update to 5.0.0.0.5.116
Dell EMC Unity Operating Environment (OE) - update to 5.0.0.0.5.116

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins