Vulnerabilities > CVE-2003-0037 - Remote Memory Corruption vulnerability in Noffle

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
noffle
nessus

Summary

Buffer overflows in noffle news server 1.0.1 and earlier allow remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code.

Vulnerable Configurations

Part Description Count
Application
Noffle
1

Nessus

NASL familyDebian Local Security Checks
NASL idDEBIAN_DSA-244.NASL
descriptionDan Jacobson noticed a problem in noffle, an offline news server, that leads to a segmentation fault. It is not yet clear whether this problem is exploitable. However, if it is, a remote attacker could trigger arbitrary code execution under the user that calls noffle, probably news.
last seen2020-06-01
modified2020-06-02
plugin id15081
published2004-09-29
reporterThis script is Copyright (C) 2004-2019 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/15081
titleDebian DSA-244-1 : noffle - buffer overflows