CVE-2012-0806

medium
Published 2012-01-27 · Modified 2026-04-29
CVSS v3
CVSS v2
6.5
VIR risk
6.5

Description

Buffer overflow in Bip 0.8.8 and earlier might allow remote authenticated users to execute arbitrary code via vectors involving a series of TCP connections that triggers use of many open file descriptors.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2012-0806

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://projects.duckcorp.org/projects/bip/repository/revisions/222a33cb84a2e52ad55a88900b7895bf9dd0262c

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://projects.duckcorp.org/issues/269

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/47679

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://openwall.com/lists/oss-security/2012/01/24/10

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=657217

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed0.8.8-2
debian debianbullseyefixed0.8.8-2
debian debianforkyfixed0.8.8-2
debian debiansidfixed0.8.8-2
debian debiantrixiefixed0.8.8-2

Application impact

VendorProductVersionsFixed
duckcorpbip{"endIncluding":"0.8.8"}
duckcorpbip0.7.0
duckcorpbip0.7.1
duckcorpbip0.7.2
duckcorpbip0.7.3
duckcorpbip0.7.4
duckcorpbip0.7.5
duckcorpbip0.8.0
duckcorpbip0.8.1
duckcorpbip0.8.2
duckcorpbip0.8.3
duckcorpbip0.8.4
duckcorpbip0.8.5
duckcorpbip0.8.6
duckcorpbip0.8.7

References

CWEs

CWE-119

Verify integrity in audit chain (admin only). AS-IS.