5

CVE-2004-1702

Exploit

The AuthenticationDialogue function in cfservd for Cfengine 2.0.0 to 2.1.7p1 does not properly check the return value of the ReceiveTransaction function, which leads to a failed malloc call and triggers to a null dereference, which allows remote attackers to cause a denial of service (crash).

Data is provided by the National Vulnerability Database (NVD)
GnuCfengine Version2.0.0
GnuCfengine Version2.0.1
GnuCfengine Version2.0.2
GnuCfengine Version2.0.3
GnuCfengine Version2.0.4
GnuCfengine Version2.0.5
GnuCfengine Version2.0.5 Updateb1
GnuCfengine Version2.0.5 Updatepre
GnuCfengine Version2.0.5 Updatepre2
GnuCfengine Version2.0.6
GnuCfengine Version2.0.7
GnuCfengine Version2.0.7 Updatep1
GnuCfengine Version2.0.7 Updatep2
GnuCfengine Version2.0.7 Updatep3
GnuCfengine Version2.0.8
GnuCfengine Version2.0.8 Updatep1
GnuCfengine Version2.1.0 Updatea6
GnuCfengine Version2.1.0 Updatea8
GnuCfengine Version2.1.0 Updatea9
GnuCfengine Version2.1.7 Updatep1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 2.12% 0.825
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P