CVE-2013-0249 describes a stack-based buffer overflow in the Curl_sasl_create_digest_md5_message function within libcurl versions 7.26.0 to 7.28.1, affecting products like Haxx curl and Canonical Ubuntu. This vulnerability allows remote attackers to trigger a denial of service or potentially execute arbitrary code by sending a long string in the realm parameter during SASL DIGEST-MD5 authentication for POP3, SMTP, or IMAP. With a CVSS score of 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P) and a FAUCET Risk Score of 98/100, it represents a high-severity risk due to its network-based attack vector and low attack complexity. While not listed in CISA's KEV catalog or currently active on hot lists, a Proof-of-Concept exploit (EDB-24487) is publicly available, though there is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.26.0CPE matchmatch criteria | cpe:2.3:a:haxx:curl:7.26.0:*:*:*:*:*:*:* | ||
7.27.0CPE matchmatch criteria | cpe:2.3:a:haxx:curl:7.27.0:*:*:*:*:*:*:* | ||
7.28.0CPE matchmatch criteria | cpe:2.3:a:haxx:curl:7.28.0:*:*:*:*:*:*:* | ||
7.28.1CPE matchmatch criteria | cpe:2.3:a:haxx:curl:7.28.1:*:*:*:*:*:*:* | ||
7.26.0CPE matchmatch criteria | cpe:2.3:a:haxx:libcurl:7.26.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
curl: Stack-based buffer overflow when negotiating SASL DIGEST-MD5 authentication with IMAP, POP3 and SMTP protocols
Feb 6, 2013SASL buffer overflow
Feb 6, 2013SASL buffer overflow
Feb 6, 2013