7.5

CVE-2003-0849

Buffer overflow in net.c for cfengine 2.x before 2.0.8 allows remote attackers to execute arbitrary code via certain packets with modified length values, which is trusted by the ReceiveTransaction function when using a buffer provided by the BusyWithConnection function.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GnuCfengine Version2.0.0
GnuCfengine Version2.0.1
GnuCfengine Version2.0.2
GnuCfengine Version2.0.3
GnuCfengine Version2.0.4
GnuCfengine Version2.0.5
GnuCfengine Version2.0.5 Updateb1
GnuCfengine Version2.0.5 Updatepre
GnuCfengine Version2.0.5 Updatepre2
GnuCfengine Version2.0.6
GnuCfengine Version2.0.7
GnuCfengine Version2.0.7 Updatep1
GnuCfengine Version2.0.7 Updatep2
GnuCfengine Version2.0.7 Updatep3
GnuCfengine Version2.1.0 Updatea6
GnuCfengine Version2.1.0 Updatea8
GnuCfengine Version2.1.0 Updatea9
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 7.68% 0.91
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P