{"id":"UBUNTU-CVE-2013-0288","details":"nss-pam-ldapd before 0.7.18 and 0.8.x before 0.8.11 allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code by performing a name lookup on an application with a large number of open file descriptors, which triggers a stack-based buffer overflow related to incorrect use of the FD_SET macro.","modified":"2025-07-16T08:10:40.207437Z","published":"2013-03-05T21:38:00Z","withdrawn":"2025-07-18T16:42:49Z","upstream":["CVE-2013-0288"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2013-0288"},{"type":"REPORT","url":"http://arthurdejong.org/nss-pam-ldapd/CVE-2013-0288"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2013-0288"}],"affected":[{"package":{"name":"nss-pam-ldapd","ecosystem":"Ubuntu:14.04:LTS","purl":"pkg:deb/ubuntu/nss-pam-ldapd@0.8.13-3?arch=source&distro=trusty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.8.13-3"}]}],"versions":["0.8.13-1"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"libnss-ldapd","binary_version":"0.8.13-3"},{"binary_name":"libpam-ldapd","binary_version":"0.8.13-3"},{"binary_name":"nslcd","binary_version":"0.8.13-3"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2013/UBUNTU-CVE-2013-0288.json"}}],"schema_version":"1.7.3","severity":[{"type":"Ubuntu","score":"medium"}]}