PT-2004-1083 · Apache · Openoffice+1

Thomas Wana

·

Publicado

2004-04-15

·

Atualizado

2020-10-13

·

CVE-2004-0179

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions neon versions 0.24.4 and earlier Cadaver (affected versions not specified) Subversion versions 0.27.0 and earlier OpenOffice (affected versions not specified)
Description The issue allows remote malicious WebDAV servers to execute arbitrary code due to multiple format string vulnerabilities. This can lead to a violation of confidentiality, integrity, and availability of protected information. The vulnerability can be exploited remotely.
Recommendations For neon versions 0.24.4 and earlier, update to a version later than 0.24.4. For Cadaver, Subversion, and OpenOffice, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use of Externally-Controlled Format String

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-07906
BDU:2015-07907
CVE-2004-0179
DSA-487
RHSA-2004:160

Produtos afetados

Openoffice
Subversion