CVE-2011-5268

UnknownEPSS 1.50%

Last modified

CVE-2011-5268 is a vulnerability of currently unknown severity. connection.c in Bip before 0.8.9 does not properly close sockets, which allows remote attackers to cause a denial of service (file descriptor consumption and crash) via multiple failed SSL handshakes, a different vulnerability than CVE-2013-4550. NOTE: this issue was SPLIT from CVE-2013-4550 because it is a different type of issue.. EPSS estimates a 1.50% chance of exploitation in the next 30 days.

Description

connection.c in Bip before 0.8.9 does not properly close sockets, which allows remote attackers to cause a denial of service (file descriptor consumption and crash) via multiple failed SSL handshakes, a different vulnerability than CVE-2013-4550. NOTE: this issue was SPLIT from CVE-2013-4550 because it is a different type of issue.

Metrics

EPSS Probability
1.50%

71.0th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
DuckcorpBip<= 0.8.8
DuckcorpBip0.8.0
DuckcorpBip0.8.1
DuckcorpBip0.8.2
DuckcorpBip0.8.3
DuckcorpBip0.8.4
DuckcorpBip0.8.5
DuckcorpBip0.8.6
DuckcorpBip0.8.7
FedoraprojectFedora18
FedoraprojectFedora19
FedoraprojectFedora20

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2011-5268?
connection.c in Bip before 0.8.9 does not properly close sockets, which allows remote attackers to cause a denial of service (file descriptor consumption and crash) via multiple failed SSL handshakes, a different vulnerability than CVE-2013-4550. NOTE: this issue was SPLIT from CVE-2013-4550 because it is a different type of issue.
How severe is CVE-2011-5268?
Severity scoring for CVE-2011-5268 is pending analysis. The EPSS model estimates a 1.50% probability of exploitation in the next 30 days.
How do I fix CVE-2011-5268?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2011-5268?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST