PT-2004-3301 · Samhain · Samhain
Published
2004-12-31
·
Updated
2017-07-11
·
CVE-2004-2409
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Samhain versions 1.8.9 through 2.0.1
Description:
A buffer overflow issue exists in the
sh hash compdata function when running in update mode, potentially allowing attackers to execute arbitrary code.Recommendations:
For Samhain versions 1.8.9 through 2.0.1, consider disabling the update mode until a patch is available. Restrict access to the
sh hash compdata function to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Samhain