PT-2005-1080 · Open+1 · Openmotif+1

Published

2005-12-02

·

Updated

2018-10-19

·

CVE-2005-3964

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions OpenMotif versions 2.1.30 through 2.2.3 OpenMotif version 2.2.3 OpenMotif versions prior to 2.2.3-r8
Description The issue allows attackers to execute arbitrary code via the diag issue diagnostic function in UilDiags.c and the open source file function in UilSrcSrc.c, potentially leading to disruption of confidentiality, integrity, and availability of protected information. Exploitation can be carried out remotely.
Recommendations For OpenMotif versions 2.1.30 through 2.2.3, consider disabling the diag issue diagnostic and open source file functions until a patch is available. For OpenMotif versions prior to 2.2.3-r8, update to version 2.2.3-r8 or later to resolve the issue. At the moment, there is no information about additional mitigation measures for other affected versions.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-07462
BDU:2015-07463
BDU:2015-07464
BDU:2015-07465
BDU:2015-07466
BDU:2015-09490
CVE-2005-3964
RHSA-2006:0272
RHSA-2006_0272
RHSA-2008:0261
RHSA-2008:0524

Affected Products

Openmotif
Red Hat