PT-2004-1507 · Gnu · Gnu Anubis
Ulf Harnhammar
·
Published
2004-03-18
·
Updated
2017-07-11
·
CVE-2004-0353
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
GNU Anubis versions 3.6.0 through 3.6.2
GNU Anubis versions 3.9.92 and 3.9.93
Description
The issue is related to multiple buffer overflows in the
auth ident() function in auth.c. This allows remote attackers to gain privileges via a long string.Recommendations
For GNU Anubis versions 3.6.0 through 3.6.2, consider updating to a version that fixes the buffer overflows in the
auth ident() function.
For GNU Anubis versions 3.9.92 and 3.9.93, consider updating to a version that fixes the buffer overflows in the auth ident() function.
As a temporary workaround, consider restricting access to the auth ident() function until a patch is available.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gnu Anubis