lists.omnipotent.netConfirmation
http://lists.omnipotent.net/pipermail/lcdproc/2004-April/008884.html CVE-2004-1915
lcdproc lcdd 0.x/4.x - Multiple Vulnerabilities
Record summary
CVE-2004-1915 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Buffer overflow in the parse_all_client_messages function in LCDproc 0.4.x up to 0.4.4 allows remote attackers to execute arbitrary code via a large number of arguments.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBlcdproc lcdd 0.x/4.x - Multiple VulnerabilitiesExploitDB exploitby wsxzNot analyzed1 file
References
720040408 PSR - #2004-001 Remote - LCDProcmailing list
http://marc.info/?l=bugtraq&m=108145722229810&w=2 11333Third-party advisory
http://secunia.com/advisories/11333 GLSA-200404-19Vendor advisory
http://security.gentoo.org/glsa/glsa-200404-19.xml 10085vdb entry
http://www.securityfocus.com/bid/10085 lcdproc-parseallclientmessages-bo(15803)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/15803 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2004-1915