Vulnerabilities > CVE-2001-0441
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Buffer overflow in (1) wrapping and (2) unwrapping functions of slrn news reader before 0.9.7.0 allows remote attackers to execute arbitrary commands via a long message header.
Vulnerable Configurations
Nessus
NASL family Mandriva Local Security Checks NASL id MANDRAKE_MDKSA-2001-028.NASL description A buffer overflow exists in versions of the slrn news reader prior to 0.9.6.3pl4 as reported by Bill Nottingham. This problem exists in the wrapping/unwrapping functions and a long header in a message might overflow a buffer which could result in execution of arbitrary code encoded in the message. last seen 2020-06-01 modified 2020-06-02 plugin id 61902 published 2012-09-06 reporter This script is Copyright (C) 2012-2019 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/61902 title Mandrake Linux Security Advisory : slrn (MDKSA-2001:028) NASL family Debian Local Security Checks NASL id DEBIAN_DSA-040.NASL description Bill Nottingham reported a problem in the wrapping/unwrapping functions of the slrn newsreader. A long header in a message might overflow a buffer, which could result in executing arbitrary code encoded in the message. The default configuration does not have wrapping enable, but it can easily be enabled either by changing the configuration or pressing W while viewing a message. last seen 2020-06-01 modified 2020-06-02 plugin id 14877 published 2004-09-29 reporter This script is Copyright (C) 2004-2019 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/14877 title Debian DSA-040-1 : slrn - buffer overflow
Redhat
advisories |
|
References
- http://archives.neohapsis.com/archives/freebsd/2001-04/0610.html
- http://archives.neohapsis.com/archives/freebsd/2001-04/0610.html
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000383
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000383
- http://marc.info/?l=bugtraq&m=98471253131191&w=2
- http://marc.info/?l=bugtraq&m=98471253131191&w=2
- http://www.debian.org/security/2001/dsa-040
- http://www.debian.org/security/2001/dsa-040
- http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-028.php3
- http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-028.php3
- http://www.redhat.com/support/errata/RHSA-2001-028.html
- http://www.redhat.com/support/errata/RHSA-2001-028.html
- http://www.securityfocus.com/bid/2493
- http://www.securityfocus.com/bid/2493
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6213
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6213