PT-2003-1036 · Xfstt · Xfstt
Vade79
·
Published
2003-08-01
·
Updated
2024-02-15
·
CVE-2003-0625
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
xfstt (affected versions not specified)
Description
The issue is related to an off-by-one error in xfstt, allowing remote attackers to read potentially sensitive memory via a malformed client request in the connection handshake. This can lead to a leak of memory in the server's response, potentially compromising confidentiality. Multiple vulnerabilities in the xfstt package may also lead to disruptions in the integrity and availability of protected information, with exploitation possible remotely.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Xfstt