← Vulnerability feed

Vulnerability record · CVE-2007-2711 · published 16 May 2007

CVE-2007-2711: TinyIdentD stack buffer overflow via TCP port 113

Tinyirc · Tinyidentd

TinyIdentD 2.2 and earlier contains a stack-based buffer overflow reachable by sending a long string to TCP port 113. A remote, unauthenticated attacker can overwrite stack memory and potentially execute arbitrary code in the context of the identd service. The flaw is severe because the service is network-exposed and requires no credentials.

10.0 CVSS 2.0 High EPSS 63% · top 0.8%
10.0CVSS 2.0 base score
63%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in TinyIdentD 2.2 and earlier allows remote attackers to execute arbitrary code via a long string to TCP port 113.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityThe flaw is remotely exploitable without authentication and has a public exploit plus very high EPSS, though it is not in CISA KEV and the affected product is legacy.

What it is

TinyIdentD 2.2 and earlier contains a stack-based buffer overflow reachable by sending a long string to TCP port 113. A remote, unauthenticated attacker can overwrite stack memory and potentially execute arbitrary code in the context of the identd service. The flaw is severe because the service is network-exposed and requires no credentials.

Impact

Successful exploitation allows remote code execution with the privileges of the TinyIdentD process, giving the attacker full control of the affected host. Even without code execution, the overflow can crash the service, causing a denial of service.

Attack surface

The vulnerability is reached over the network by connecting to TCP port 113 and sending an oversized string; no authentication or user interaction is required per the CVSS vector AV:N/AC:L/Au:N. Any host exposing TinyIdentD to untrusted networks is directly reachable.

Exploitation

CISA KEV does not list this CVE, but EPSS is high (0.627, 99th percentile) and a public exploit reference is tagged on SecurityFocus BID 23981, indicating exploit code is publicly available.

What to do

  • Upgrade TinyIdentD to a version later than 2.2 if one is available; the record does not name a fixed version, so verify with the vendor.
  • If no patch exists, disable or remove the identd service where it is not required.
  • Restrict TCP port 113 to trusted hosts using firewall or ACL rules, and never expose it to the internet.
  • Run the service under a low-privilege account and apply OS-level exploit mitigations such as ASLR, DEP and stack canaries.
  • Monitor vendor and OSVDB/Secunia advisories for an updated release.

Detection

  • Alert on unusually long or malformed requests to TCP port 113 in IDS/IPS or network flow logs.
  • Monitor TinyIdentD process crashes or restarts, which may indicate overflow attempts.
  • Watch for unexpected child processes or outbound connections originating from the identd service account.
  • Review firewall logs for external connections to port 113 on hosts running TinyIdentD.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-2711 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Source: NIST National Vulnerability Database (record CVE-2007-2711), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.