PT-2004-1073 · Gnu+1 · Sharutils+1
Publicado
2004-12-31
·
Atualizado
2017-10-11
·
CVE-2004-1773
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
sharutils versions 4.2.1 and earlier
Description
The issue concerns multiple buffer overflows in the sharutils package, which can be exploited to execute arbitrary code. This can be achieved via long output from
wc to shar, or through unknown vectors in unshar. Exploitation of these issues may lead to a breach of confidentiality, integrity, and availability of protected information, and can be performed remotely.Recommendations
For sharutils versions 4.2.1 and earlier, consider updating to a newer version that addresses these buffer overflows.
As a temporary workaround, consider restricting the use of
shar and unshar until a patch is available.
Avoid using wc with long output to shar in the affected versions until the issue is resolved.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Red Hat
Sharutils