Vulnerabilities > CVE-2006-0804 - Unspecified vulnerability in TIN
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN tin
nessus
Summary
Off-by-one error in TIN 1.8.0 and earlier might allow attackers to execute arbitrary code via unknown vectors that trigger a buffer overflow.
Vulnerable Configurations
Nessus
NASL family | Gentoo Local Security Checks |
NASL id | GENTOO_GLSA-200611-18.NASL |
description | The remote host is affected by the vulnerability described in GLSA-200611-18 (TIN: Multiple buffer overflows) Urs Janssen and Aleksey Salow have reported multiple buffer overflows in TIN. Additionally, the OpenPKG project has reported an allocation off-by-one flaw which can lead to a buffer overflow. Impact : An attacker could entice a TIN user to read a specially crafted news article, and execute arbitrary code with the rights of the user running TIN. Workaround : There is no known workaround at this time. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 23726 |
published | 2006-11-27 |
reporter | This script is Copyright (C) 2006-2019 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/23726 |
title | GLSA-200611-18 : TIN: Multiple buffer overflows |
code |
|
References
- http://secunia.com/advisories/19130
- http://secunia.com/advisories/19130
- http://security.gentoo.org/glsa/glsa-200611-18.xml
- http://security.gentoo.org/glsa/glsa-200611-18.xml
- http://www.novell.com/linux/security/advisories/2006_05_sr.html
- http://www.novell.com/linux/security/advisories/2006_05_sr.html
- http://www.openpkg.org/security/OpenPKG-SA-2006.005-tin.html
- http://www.openpkg.org/security/OpenPKG-SA-2006.005-tin.html
- http://www.securityfocus.com/bid/16728
- http://www.securityfocus.com/bid/16728
- http://www.vupen.com/english/advisories/2006/0702
- http://www.vupen.com/english/advisories/2006/0702
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24841
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24841