tigger.uic.edu
http://tigger.uic.edu/~jlongs2/holes/pcal.txt CVE-2004-1289
PCAL 4.x - Calendar File 'getline' Remote Buffer Overflow
Record summary
CVE-2004-1289 has a selected CVSS score of 10.0; EIP currently links 2 catalogued exploits.
Description
Multiple buffer overflows in (1) the getline function in pcalutil.c and (2) the get_holiday function in readfile.c for pcal 4.7.1 allow remote attackers to execute arbitrary code via a crafted calendar file.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBPCAL 4.x - Calendar File 'getline' Remote Buffer OverflowExploitDB exploitby Danny LungstromNot analyzed1 file
ExploitDBPCAL 4.x - Calendar File 'get_holiday' Remote Buffer OverflowExploitDB exploitby Danny LungstromNot analyzed1 file
References
3pcal-getline-pcalutil-bo(18552)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/18552 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2004-1289