Vulnerabilities > CVE-2004-1288 - Unspecified vulnerability in Siag O3Read .3

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
siag
critical
nessus
exploit available

Summary

Buffer overflow in the parse_html function in o3read.c for o3read 0.0.3 allows remote attackers to execute arbitrary code via a crafted SXW file.

Vulnerable Configurations

Part Description Count
Application
Siag
1

Exploit-Db

descriptionO3Read 0.0.3 HTML Parser Buffer Overflow Vulnerability. CVE-2004-1288. Remote exploit for linux platform
idEDB-ID:25010
last seen2016-02-03
modified2004-12-17
published2004-12-17
reporterWiktor Kopec
sourcehttps://www.exploit-db.com/download/25010/
titleO3Read 0.0.3 HTML Parser Buffer Overflow Vulnerability

Nessus

NASL familyGentoo Local Security Checks
NASL idGENTOO_GLSA-200501-20.NASL
descriptionThe remote host is affected by the vulnerability described in GLSA-200501-20 (o3read: Buffer overflow during file conversion) Wiktor Kopec discovered that the parse_html function in o3read.c copies any number of bytes into a 1024-byte t[] array. Impact : Using a specially crafted file, possibly delivered by e-mail or over the Web, an attacker may execute arbitrary code with the permissions of the user running o3read. Workaround : There is no known workaround at this time.
last seen2020-06-01
modified2020-06-02
plugin id16411
published2005-02-14
reporterThis script is Copyright (C) 2005-2019 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/16411
titleGLSA-200501-20 : o3read: Buffer overflow during file conversion