CVE-2010-3071

NameCVE-2010-3071
Descriptionbip before 0.8.6 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an empty USER command.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs595409

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
bip (PTS)jessie0.8.9-1fixed
stretch0.8.9-1.1fixed
buster0.9.0~rc3-1fixed
bullseye0.9.0~rc4-1fixed
bookworm0.9.3-1fixed
sid, trixie0.9.3-1.1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
bipsourcelenny(not affected)
bipsourcesqueeze0.8.2-1squeeze2
bipsource(unstable)0.8.6-1low595409

Notes

[lenny] - bip <not-affected> (vulnerable code ('LINK(lc)->name') not in 0.7.4-2)

Search for package or bug name: Reporting problems