| Vulnerability Name: | CVE-2008-7224 (CCN-53595) | ||||||||||||||||||||||||||||||||||||
| Assigned: | 2006-07-29 | ||||||||||||||||||||||||||||||||||||
| Published: | 2006-07-29 | ||||||||||||||||||||||||||||||||||||
| Updated: | 2017-09-29 | ||||||||||||||||||||||||||||||||||||
| Summary: | Buffer overflow in entity_cache in ELinks before 0.11.4rc0 allows remote attackers to cause a denial of service (crash) via a crafted link. | ||||||||||||||||||||||||||||||||||||
| CVSS v3 Severity: | 3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L)
| ||||||||||||||||||||||||||||||||||||
| CVSS v2 Severity: | 7.8 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C) 5.8 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C)
1.9 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
5.0 Medium (REDHAT Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||||||||||||||||||||||||||||||
| Vulnerability Type: | CWE-119 CWE-193 | ||||||||||||||||||||||||||||||||||||
| Vulnerability Consequences: | Denial of Service | ||||||||||||||||||||||||||||||||||||
| References: | Source: CCN Type: Debian Bug report logs - #380347 elinks: crashes on a specially crafted page Source: CONFIRM Type: Exploit http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=380347 Source: MITRE Type: CNA CVE-2008-7224 Source: CCN Type: Elinks Web site Elinks - Full-Featured Text WWW Browser Source: CCN Type: MLIST: elinks-users 20080204 [ANNOUNCE] ELinks 0.11.4rc0 Source: MLIST Type: UNKNOWN [elinks-users] 20080204 [ANNOUNCE] ELinks 0.11.4rc0 Source: OSVDB Type: UNKNOWN 41949 Source: CCN Type: RHSA-2009-1471 Important: elinks security update Source: DEBIAN Type: DSA-1902 elinks -- buffer overflow Source: CCN Type: OSVDB ID: 41949 ELinks entity_cache Function Overflow Source: CCN Type: BID-36574 ELinks 'entity_cache' HTML File Off By One Buffer Overflow Vulnerability Source: CCN Type: USN-851-1 Elinks vulnerabilities Source: XF Type: UNKNOWN elinks-entitycache-dos(53595) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:10126 | ||||||||||||||||||||||||||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Configuration RedHat 2: Configuration RedHat 3: Configuration RedHat 4: Configuration RedHat 5: Configuration RedHat 6: Configuration RedHat 7: Configuration RedHat 8: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||||||||||||||||||
| Oval Definitions | |||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||
| BACK | |||||||||||||||||||||||||||||||||||||