10

CVE-2004-1701

Exploit
Heap-based buffer overflow in the AuthenticationDialogue function in cfservd for Cfengine 2.0.0 to 2.1.7p1 allows remote attackers to execute arbitrary code via a long SAUTH command during RSA authentication.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gnu ≫ Cfengine Version 2.0.0
Gnu ≫ Cfengine Version 2.0.1
Gnu ≫ Cfengine Version 2.0.2
Gnu ≫ Cfengine Version 2.0.3
Gnu ≫ Cfengine Version 2.0.4
Gnu ≫ Cfengine Version 2.0.5
Gnu ≫ Cfengine Version 2.0.5 Update b1
Gnu ≫ Cfengine Version 2.0.5 Update pre
Gnu ≫ Cfengine Version 2.0.5 Update pre2
Gnu ≫ Cfengine Version 2.0.6
Gnu ≫ Cfengine Version 2.0.7
Gnu ≫ Cfengine Version 2.0.7 Update p1
Gnu ≫ Cfengine Version 2.0.7 Update p2
Gnu ≫ Cfengine Version 2.0.7 Update p3
Gnu ≫ Cfengine Version 2.0.8
Gnu ≫ Cfengine Version 2.0.8 Update p1
Gnu ≫ Cfengine Version 2.1.0 Update a6
Gnu ≫ Cfengine Version 2.1.0 Update a8
Gnu ≫ Cfengine Version 2.1.0 Update a9
Gnu ≫ Cfengine Version 2.1.7 Update p1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 19.51% 0.97
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://marc.info/?l=bugtraq&m=109208394910086&w=2
http://marc.info/?l=bugtraq&m=110886670528775&w=2
http://secunia.com/advisories/12251
Patch
Vendor Advisory
http://security.gentoo.org/glsa/glsa-200408-08.xml
Patch
Vendor Advisory
Exploit
http://www.coresecurity.com/common/showdoc.php?idx=387&idxseccion=10
Patch
Vendor Advisory
Exploit
http://www.securityfocus.com/bid/10899
Patch
Vendor Advisory
Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/16935