7.5

CVE-2003-0721

Exploit
Integer signedness error in rfc2231_get_param from strings.c in PINE before 4.58 allows remote attackers to execute arbitrary code via an email that causes an out-of-bounds array access using a negative number.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
WashingtonPine Version < 4.58
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.86% 0.888
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-129 Improper Validation of Array Index

The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.

http://marc.info/?l=bugtraq&m=106329356702508&w=2
Third Party Advisory
http://www.idefense.com/advisory/09.10.03.txt
Patch
Vendor Advisory
Exploit
Broken Link
http://www.redhat.com/support/errata/RHSA-2003-273.html
Patch
Vendor Advisory
Broken Link
http://www.redhat.com/support/errata/RHSA-2003-274.html
Broken Link
http://lists.grok.org.uk/pipermail/full-disclosure/2003-September/009850.html
Broken Link
http://marc.info/?l=bugtraq&m=106367213400313&w=2
Third Party Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A503
Broken Link