5
CVE-2007-4450
- EPSS 1.53%
- Veröffentlicht 21.08.2007 00:17:00
- Zuletzt bearbeitet 16.06.2026 22:44:07
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
The server in Toribash 2.71 and earlier does not properly handle long commands, which allows remote attackers to trigger a protocol violation in which data is sent to other clients without a required LF character, as demonstrated by a SAY command. NOTE: the security impact of this violation is not clear, although it probably makes exploitation of CVE-2007-4449 easier.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.53% | 0.715 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:P
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
http://aluigi.org/poc/toribashish.zip
http://secunia.com/advisories/26507
http://securityreason.com/securityalert/3033
http://www.securityfocus.com/archive/1/477025/100/0/threaded
http://www.securityfocus.com/bid/25359