CVE-2004-1701

GNU Cfengine - Buffer Overflow

Title source: rule

Description

Heap-based buffer overflow in the AuthenticationDialogue function in cfservd for Cfengine 2.0.0 to 2.1.7p1 allows remote attackers to execute arbitrary code via a long SAUTH command during RSA authentication.

Exploits (2)

exploitdb WORKING POC VERIFIED
by jsk · cremotelinux
https://www.exploit-db.com/exploits/24361
exploitdb WORKING POC VERIFIED
by Juan Pablo Martinez Kuhn · pythondoslinux
https://www.exploit-db.com/exploits/24360

Scores

EPSS 0.5676
EPSS Percentile 98.1%

Details

Status published
Products (11)
gnu/cfengine 2.0.0
gnu/cfengine 2.0.1
gnu/cfengine 2.0.2
gnu/cfengine 2.0.3
gnu/cfengine 2.0.4
gnu/cfengine 2.0.5 (4 CPE variants)
gnu/cfengine 2.0.6
gnu/cfengine 2.0.7 (4 CPE variants)
gnu/cfengine 2.0.8 (2 CPE variants)
gnu/cfengine 2.1.0 a6 (3 CPE variants)
... and 1 more
Published Aug 09, 2004
Tracked Since Feb 18, 2026