PT-2004-1507 · Gnu · Gnu Anubis
Ulf Harnhammar
·
Publicado
2004-03-18
·
Atualizado
2017-07-11
·
CVE-2004-0353
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
GNU Anubis versions 3.6.0 through 3.6.2
GNU Anubis versions 3.9.92 and 3.9.93
Description
The issue is related to multiple buffer overflows in the
auth ident() function in auth.c. This allows remote attackers to gain privileges via a long string.Recommendations
For GNU Anubis versions 3.6.0 through 3.6.2, consider updating to a version that fixes the buffer overflows in the
auth ident() function.
For GNU Anubis versions 3.9.92 and 3.9.93, consider updating to a version that fixes the buffer overflows in the auth ident() function.
As a temporary workaround, consider restricting access to the auth ident() function until a patch is available.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Gnu Anubis