5

CVE-2004-1702

Exploit
The AuthenticationDialogue function in cfservd for Cfengine 2.0.0 to 2.1.7p1 does not properly check the return value of the ReceiveTransaction function, which leads to a failed malloc call and triggers to a null dereference, which allows remote attackers to cause a denial of service (crash).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gnu ≫ Cfengine Version 2.0.0
Gnu ≫ Cfengine Version 2.0.1
Gnu ≫ Cfengine Version 2.0.2
Gnu ≫ Cfengine Version 2.0.3
Gnu ≫ Cfengine Version 2.0.4
Gnu ≫ Cfengine Version 2.0.5
Gnu ≫ Cfengine Version 2.0.5 Update b1
Gnu ≫ Cfengine Version 2.0.5 Update pre
Gnu ≫ Cfengine Version 2.0.5 Update pre2
Gnu ≫ Cfengine Version 2.0.6
Gnu ≫ Cfengine Version 2.0.7
Gnu ≫ Cfengine Version 2.0.7 Update p1
Gnu ≫ Cfengine Version 2.0.7 Update p2
Gnu ≫ Cfengine Version 2.0.7 Update p3
Gnu ≫ Cfengine Version 2.0.8
Gnu ≫ Cfengine Version 2.0.8 Update p1
Gnu ≫ Cfengine Version 2.1.0 Update a6
Gnu ≫ Cfengine Version 2.1.0 Update a8
Gnu ≫ Cfengine Version 2.1.0 Update a9
Gnu ≫ Cfengine Version 2.1.7 Update p1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.41% 0.819
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://marc.info/?l=bugtraq&m=109208394910086&w=2
http://secunia.com/advisories/12251
Patch
Vendor Advisory
http://security.gentoo.org/glsa/glsa-200408-08.xml
Patch
Vendor Advisory
Exploit
http://www.coresecurity.com/common/showdoc.php?idx=387&idxseccion=10
Patch
Vendor Advisory
Exploit
http://www.securityfocus.com/bid/10900
Patch
Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/16937