Back to Database
Status published
Critical
CVE-2013-2298
Multiple stack-based buffer overflows in the XML parser in BOINC...
Vulnerability Description
Multiple stack-based buffer overflows in the XML parser in BOINC 7.x allow attackers to have unspecified impact via a crafted XML file, related to the scheduler.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2013-2298
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.openwall.com/lists/oss-security/2013/04/28/3
- http://lists.fedoraproject.org/pipermail/package-announce/2013-December/125125.html
- http://secunia.com/advisories/53192
- https://exchange.xforce.ibmcloud.com/vulnerabilities/83931
- http://boinc.berkeley.edu/gitweb/?p=boinc-v2.git%3Ba=commitdiff%3Bh=2fea03824925cbcb976f4191f4d8321e41a4d95b
- http://thread.gmane.org/gmane.comp.distributed.boinc.user/3741
- http://lists.fedoraproject.org/pipermail/package-announce/2013-December/125128.html
- http://www.securityfocus.com/bid/59539
More from universityofcalifornia
View All →CVE-2018-1000875
Berkeley Open Infrastructure for Network Computing BOINC Server and Website...
Critical
9.8
CVE-2013-7386
Format string vulnerability in the PROJECT::write_account_file function in client/cs_account.cpp in...
Medium
5
CVE-2013-2019
Stack-based buffer overflow in BOINC 6.10.58 and 6.12.34 allows remote...
Critical
9.3
CVE-2011-5280
Multiple stack-based buffer overflows in BOINC 6.13.x allow remote attackers...
Medium
5
Affected Vendor
universityofcalifornia
View all reports →Affected Software
boinc client
Vulnerable Versions:
7.0, 7.0.1, 7.0.2, 7.0.3, 7.0.5, 7.0.6, 7.0.7, 7.0.8, 7.0.9, 7.0.10, 7.0.11, 7.0.12, 7.0.13, 7.0.14, 7.0.15, 7.0.16, 7.0.17, 7.0.18, 7.0.19, 7.0.20, 7.0.21, 7.0.22, 7.0.23, 7.0.24, 7.0.25, 7.0.26, 7.0.27, 7.0.28, 7.0.29, 7.0.30, 7.0.31, 7.0.32, 7.0.33, 7.0.34, 7.0.35, 7.0.36, 7.0.45, 7.0.46, 7.0.47, 7.0.48, 7.0.49, 7.0.50, 7.0.51, 7.0.52, 7.0.53, 7.0.54, 7.0.55, 7.0.56, 7.0.57, 7.0.58, 7.0.59, 7.0.60, 7.0.61, 7.0.62, 7.0.63, 7.0.64, 7.0.65, 7.0.66, 7.0.67, 7.0.68, 7.0.69, 7.0.70, 7.0.71, 7.0.72, 7.0.73, 7.0.74, 7.0.75, 7.0.76, 7.0.77, 7.0.78, 7.0.79, 7.0.80, 7.1.0, 7.1.1, 7.1.2, 7.1.3, 7.1.4, 7.1.5, 7.1.6, 7.1.7, 7.1.8, 7.1.9, 7.1.10, 7.1.11, 7.1.12, 7.1.13, 7.1.14, 7.1.15, 7.1.16, 7.1.17, 7.1.18, 7.1.19, 7.1.20, 7.1.21, 7.2.0, 7.2.1, 7.2.2, 7.2.3, 7.2.4, 7.2.5, 7.2.6, 7.2.7, 7.2.8, 7.2.9, 7.2.10, 7.2.11, 7.2.12, 7.2.13, 7.2.14, 7.2.15, 7.2.16, 7.2.17, 7.2.18, 7.2.19, 7.2.20, 7.2.21, 7.2.22, 7.2.23, 7.2.24, 7.2.25, 7.2.26, 7.2.27, 7.2.28, 7.2.29, 7.2.31, 7.2.32, 7.2.33, 7.2.34, 7.2.35, 7.2.36, 7.2.37, 7.2.38, 7.2.39, 7.2.40, 7.2.41, 7.2.42, 7.2.43, 7.2.44, 7.2.47, 7.3.0, 7.3.1, 7.3.2, 7.3.3, 7.3.4, 7.3.5, 7.3.6, 7.3.7, 7.3.8, 7.3.9, 7.3.10, 7.3.11, 7.3.12, 7.3.13, 7.3.14, 7.3.15, 7.3.16, 7.3.17, 7.3.18, 7.3.19
Timeline
Official Publish:
June 2nd, 2014
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.