Vulnerability Name:

CVE-2004-0510 (CCN-16738)

Assigned:2004-07-19
Published:2004-07-19
Updated:2017-07-11
Summary:Multiple buffer overflows in MMDF on OpenServer 5.0.6 and 5.0.7, and possibly other operating systems, may allow attackers to execute arbitrary code, as demonstrated via the execmail program.
CVSS v3 Severity:9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
7.2 High (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-Other
Vulnerability Consequences:Gain Access
References:Source: SCO
Type: UNKNOWN
SCOSA-2004.7

Source: CCN
Type: SCO Security Advisory SCOSA-2004.7
OpenServer 5.0.6 OpenServer 5.0.7 : MMDF Various buffer overflows and other security issues

Source: MITRE
Type: CNA
CVE-2004-0510

Source: BUGTRAQ
Type: UNKNOWN
20041027 MMDF deliver local root exploit for SCO OpenServer 5.0.7 x86

Source: MISC
Type: UNKNOWN
http://www.deprotect.com/advisories/DEPROTECT-20040206.txt

Source: CCN
Type: OSVDB ID: 8095
SCO OpenServer MMDF execmail Overflow

Source: BID
Type: Exploit, Patch, Vendor Advisory
10758

Source: CCN
Type: BID-10758
SCO Multi-channel Memorandum Distribution Facility Multiple Vulnerabilities

Source: XF
Type: UNKNOWN
openserver-mmdf-bo(16738)

Source: XF
Type: UNKNOWN
openserver-mmdf-bo(16738)

Vulnerable Configuration:Configuration 1:
  • cpe:/o:sco:openserver:5.0.6:*:*:*:*:*:*:*
  • OR cpe:/o:sco:openserver:5.0.6a:*:*:*:*:*:*:*
  • OR cpe:/o:sco:openserver:5.0.7:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    sco openserver 5.0.6
    sco openserver 5.0.6a
    sco openserver 5.0.7