[bug-anubis] 20040228 Important security updatemailing list
http://mail.gnu.org/archive/html/bug-anubis/2004-02/msg00000.html CVE-2004-0353
GNU Anubis 3.6.x/3.9.x - 'auth.c auth_ident()' Remote Overflow
Record summary
CVE-2004-0353 has a selected CVSS score of 10.0; EIP currently links 1 catalogued exploit.
Description
Multiple buffer overflows in auth_ident() function in auth.c for GNU Anubis 3.6.0 through 3.6.2, 3.9.92 and 3.9.93 allow remote attackers to gain privileges via a long string.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBGNU Anubis 3.6.x/3.9.x - 'auth.c auth_ident()' Remote OverflowExploitDB exploitby CMNNot analyzed1 file
References
620040304 GNU Anubis buffer overflows and format string bugsmailing list
http://marc.info/?l=bugtraq&m=107843915424588&w=2 20040310 GNU Anubis 3.6.2 remote root exploitmailing list
http://marc.info/?l=bugtraq&m=107894315012081&w=2 9772vdb entry
http://www.securityfocus.com/bid/9772 anubis-ident-bo(15345)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/15345 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2004-0353