PT-2003-1036 · Xfstt · Xfstt

Vade79

·

Published

2003-08-01

·

Updated

2024-02-15

·

CVE-2003-0625

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions xfstt (affected versions not specified)
Description The issue is related to an off-by-one error in xfstt, allowing remote attackers to read potentially sensitive memory via a malformed client request in the connection handshake. This can lead to a leak of memory in the server's response, potentially compromising confidentiality. Multiple vulnerabilities in the xfstt package may also lead to disruptions in the integrity and availability of protected information, with exploitation possible remotely.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

BDU:2015-04058
CVE-2003-0625
DSA-360

Affected Products

Xfstt