Vulnerabilities > CVE-2004-1482 - Unspecified vulnerability in BNC
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN bnc
nessus
Summary
The sbuf_getmsg function in BNC incorrectly handles backspace characters, which could allow remote attackers to bypass authentication and gain access to arbitrary scripts.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 6 |
Nessus
NASL family | Gentoo Local Security Checks |
NASL id | GENTOO_GLSA-200410-13.NASL |
description | The remote host is affected by the vulnerability described in GLSA-200410-13 (BNC: Input validation flaw) A flaw exists in the input parsing of BNC where part of the sbuf_getmsg() function handles the backspace character incorrectly. Impact : A remote user could issue commands using fake authentication credentials and possibly gain access to scripts running on the client side. Workaround : There is no known workaround at this time. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 15476 |
published | 2004-10-15 |
reporter | This script is Copyright (C) 2004-2019 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/15476 |
title | GLSA-200410-13 : BNC: Input validation flaw |
code |
|
References
- http://secunia.com/advisories/12770/
- http://secunia.com/advisories/12770/
- http://www.gentoo.org/security/en/glsa/glsa-200410-13.xml
- http://www.gentoo.org/security/en/glsa/glsa-200410-13.xml
- http://www.gotbnc.com/changes.html#2.8.9
- http://www.gotbnc.com/changes.html#2.8.9
- http://www.osvdb.org/10596
- http://www.osvdb.org/10596
- http://www.securityfocus.com/bid/11355
- http://www.securityfocus.com/bid/11355
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17672
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17672