Vulnerability record · CVE-2007-2711 · published 16 May 2007
CVE-2007-2711: TinyIdentD stack buffer overflow via TCP port 113
Tinyirc · Tinyidentd
TinyIdentD 2.2 and earlier contains a stack-based buffer overflow reachable by sending a long string to TCP port 113. A remote, unauthenticated attacker can overwrite stack memory and potentially execute arbitrary code in the context of the identd service. The flaw is severe because the service is network-exposed and requires no credentials.
Description
Stack-based buffer overflow in TinyIdentD 2.2 and earlier allows remote attackers to execute arbitrary code via a long string to TCP port 113.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
high priorityThe flaw is remotely exploitable without authentication and has a public exploit plus very high EPSS, though it is not in CISA KEV and the affected product is legacy.
What it is
TinyIdentD 2.2 and earlier contains a stack-based buffer overflow reachable by sending a long string to TCP port 113. A remote, unauthenticated attacker can overwrite stack memory and potentially execute arbitrary code in the context of the identd service. The flaw is severe because the service is network-exposed and requires no credentials.
Impact
Successful exploitation allows remote code execution with the privileges of the TinyIdentD process, giving the attacker full control of the affected host. Even without code execution, the overflow can crash the service, causing a denial of service.
Attack surface
The vulnerability is reached over the network by connecting to TCP port 113 and sending an oversized string; no authentication or user interaction is required per the CVSS vector AV:N/AC:L/Au:N. Any host exposing TinyIdentD to untrusted networks is directly reachable.
Exploitation
CISA KEV does not list this CVE, but EPSS is high (0.627, 99th percentile) and a public exploit reference is tagged on SecurityFocus BID 23981, indicating exploit code is publicly available.
What to do
- Upgrade TinyIdentD to a version later than 2.2 if one is available; the record does not name a fixed version, so verify with the vendor.
- If no patch exists, disable or remove the identd service where it is not required.
- Restrict TCP port 113 to trusted hosts using firewall or ACL rules, and never expose it to the internet.
- Run the service under a low-privilege account and apply OS-level exploit mitigations such as ASLR, DEP and stack canaries.
- Monitor vendor and OSVDB/Secunia advisories for an updated release.
Detection
- Alert on unusually long or malformed requests to TCP port 113 in IDS/IPS or network flow logs.
- Monitor TinyIdentD process crashes or restarts, which may indicate overflow attempts.
- Watch for unexpected child processes or outbound connections originating from the identd service account.
- Review firewall logs for external connections to port 113 on hosts running TinyIdentD.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-2711 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Source: NIST National Vulnerability Database (record CVE-2007-2711), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.