Multiple buffer overflows in Overkill (0verkill) 0.15pre3 might allow local...
Vulnerability Description
Multiple buffer overflows in Overkill (0verkill) 0.15pre3 might allow local users to execute arbitrary code in the client via a long HOME environment variable in the (1) load_cfg and (2) save_cfg functions; possibly allow remote attackers to execute arbitrary code via long strings to (3) the send_message function; and, in the server, via (4) the parse_command_line function.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2004-0238
Credits & Attribution
No credits recorded in the NVD database.
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/016579.html
- http://marc.info/?l=bugtraq&m=107577335424509&w=2
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15000
- https://exchange.xforce.ibmcloud.com/vulnerabilities/14999
- http://www.securiteam.com/securitynews/5AP010KC0C.html
- http://www.securityfocus.com/bid/9550
Affected Vendor
0verkill
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.