Vulnerability Name: | CVE-2004-0105 (CCN-15247) | ||||||||
Assigned: | 2004-02-18 | ||||||||
Published: | 2004-02-18 | ||||||||
Updated: | 2017-07-11 | ||||||||
Summary: | Multiple buffer overflows in Metamail 2.7 and earlier allow remote attackers to execute arbitrary code. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Wed Feb 18 2004 - 13:40:32 CST metamail format string bugs and buffer overflows Source: VULNWATCH Type: UNKNOWN 20040218 metamail format string bugs and buffer overflows Source: MITRE Type: CNA CVE-2004-0105 Source: BUGTRAQ Type: UNKNOWN 20040218 metamail format string bugs and buffer overflows Source: CCN Type: RHSA-2004-073 metamail security update Source: CCN Type: SA10908 Metamail Message Parsing System Compromise Vulnerabilities Source: SECUNIA Type: UNKNOWN 10908 Source: CIAC Type: UNKNOWN O-083 Source: DEBIAN Type: UNKNOWN DSA-449 Source: DEBIAN Type: DSA-449 metamail -- buffer overflow Source: CCN Type: GLSA-200405-17 Multiple vulnerabilities in metamail Source: CCN Type: US-CERT VU#513062 metamail contains multiple buffer overflow vulnerabilities Source: CERT-VN Type: US Government Resource VU#513062 Source: CCN Type: GLSA 200405-17 Multiple vulnerabilities in metamail Source: MANDRAKE Type: UNKNOWN MDKSA-2004:014 Source: REDHAT Type: Patch, Vendor Advisory RHSA-2004:073 Source: BID Type: UNKNOWN 9692 Source: CCN Type: BID-9692 Metamail Multiple Buffer Overflow/Format String Handling Vulnerabilities Source: SLACKWARE Type: UNKNOWN SSA:2004-049 Source: CCN Type: slackware-security Mailing List, Wed, 18 Feb 2004 04:38:25 -0800 (PST) metamail security update (SSA:2004-049-02) Source: XF Type: UNKNOWN metamail-printheader-nonascii-bo(15247) Source: XF Type: UNKNOWN metamail-printheader-nonascii-bo(15247) Source: XF Type: UNKNOWN metamail-splitmail-subject-bo(15258) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Denotes that component is vulnerable | ||||||||
Vulnerability Name: | CVE-2004-0105 (CCN-15258) | ||||||||
Assigned: | 2004-02-18 | ||||||||
Published: | 2004-02-18 | ||||||||
Updated: | 2004-02-18 | ||||||||
Summary: | Metamail is vulnerable to a buffer overflow in the ShareThisHeader function in the splitmail.c file. A remote attacker could create a specially-crafted mail message containing a long Subject header to overflow a buffer and execute arbitrary code on the system with privileges of the user, once the message is opened. | ||||||||
CVSS v3 Severity: | 5.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Wed Feb 18 2004 - 13:40:32 CST metamail format string bugs and buffer overflows Source: MITRE Type: CNA CVE-2004-0105 Source: CCN Type: RHSA-2004-073 metamail security update Source: CCN Type: SA10908 Metamail Message Parsing System Compromise Vulnerabilities Source: DEBIAN Type: DSA-449 metamail -- buffer overflow Source: CCN Type: GLSA-200405-17 Multiple vulnerabilities in metamail Source: CCN Type: US-CERT VU#513062 metamail contains multiple buffer overflow vulnerabilities Source: CCN Type: BID-9692 Metamail Multiple Buffer Overflow/Format String Handling Vulnerabilities Source: XF Type: UNKNOWN metamail-splitmail-subject-bo(15258) | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |