PT-2004-1507 · Gnu · Gnu Anubis

Ulf Harnhammar

·

Publicado

2004-03-18

·

Atualizado

2017-07-11

·

CVE-2004-0353

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions GNU Anubis versions 3.6.0 through 3.6.2 GNU Anubis versions 3.9.92 and 3.9.93
Description The issue is related to multiple buffer overflows in the auth ident() function in auth.c. This allows remote attackers to gain privileges via a long string.
Recommendations For GNU Anubis versions 3.6.0 through 3.6.2, consider updating to a version that fixes the buffer overflows in the auth ident() function. For GNU Anubis versions 3.9.92 and 3.9.93, consider updating to a version that fixes the buffer overflows in the auth ident() function. As a temporary workaround, consider restricting access to the auth ident() function until a patch is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2004-0353

Produtos afetados

Gnu Anubis