Vulnerability record · CVE-2013-3563 · published 4 July 2013
CVE-2013-3563: Lianja SQL Server db_netserver stack buffer overflow
Lianja · Lianja Sql Server
Lianja SQL Server before 1.0.0RC5.2 contains a stack-based buffer overflow in the db_netserver component. A remote attacker can send a crafted string to TCP port 8001 to crash the daemon or potentially execute arbitrary code. The flaw is remotely reachable without authentication, making it a serious risk for exposed instances.
Description
Stack-based buffer overflow in db_netserver in Lianja SQL Server before 1.0.0RC5.2 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted string to TCP port 8001.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityRemote unauthenticated buffer overflow with public exploit code and high EPSS score, though not known to be actively exploited in the wild per KEV.
What it is
Lianja SQL Server before 1.0.0RC5.2 contains a stack-based buffer overflow in the db_netserver component. A remote attacker can send a crafted string to TCP port 8001 to crash the daemon or potentially execute arbitrary code. The flaw is remotely reachable without authentication, making it a serious risk for exposed instances.
Impact
An attacker can cause a denial of service by crashing the daemon, and may be able to execute arbitrary code in the context of the service. Successful code execution would give the attacker control over the SQL server process.
Attack surface
The vulnerability is reached over the network via TCP port 8001, with no authentication required per the CVSS vector (AV:N/AC:L/Au:N). No user interaction is indicated.
Exploitation
Public exploit code exists (Exploit-DB reference), and EPSS indicates a high likelihood of exploitation activity (0.49488, 98.8th percentile). The CVE is not listed in CISA KEV.
What to do
- Upgrade Lianja SQL Server to version 1.0.0RC5.2 or later.
- Restrict network access to TCP port 8001 to trusted hosts only.
- Place the SQL server behind a firewall or VPN and avoid exposing it directly to the internet.
- Monitor for vendor patches or updated releases if the current version cannot be upgraded immediately.
Detection
- Monitor network traffic to TCP port 8001 for unusually long or malformed strings.
- Check Lianja SQL Server logs for crashes or abnormal daemon restarts.
- Use IDS/IPS signatures for known exploit patterns targeting db_netserver.
- Alert on unexpected process terminations or restarts of the Lianja SQL Server service.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.exploit-db.com/exploits/25851/ | Exploit |
| http://www.exploit-db.com/exploits/25851/ | Exploit |
Track CVE-2013-3563 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-3563), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.