HIGH
Multiple buffer overflows in LISTSERV 14.3 and 14.4, including LISTSERV Lite and HPO, with the web archive interface enabled, allow remote attackers to execute arbitrary code via unknown attack vectors related to the WA CGI
Published Mar 7, 2006
7.5
HIGHCVSS 2.0
EPSS 7.47%
Description
Multiple buffer overflows in LISTSERV 14.3 and 14.4, including LISTSERV Lite and HPO, with the web archive interface enabled, allow remote attackers to execute arbitrary code via unknown attack vectors related to the WA CGI. NOTE: technical details will be released after the grace period has ended on 20060603.
Affected products
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (10)
- http://secunia.com/advisories/19106 third-party-advisoryx_refsource_SECUNIA
- http://securitytracker.com/id?1015722 vdb-entryx_refsource_SECTRACKPatchVendor Advisory
- http://www.kb.cert.org/vuls/id/841132 third-party-advisoryx_refsource_CERT-VNUS Government Resource
- http://www.lsoft.com/manuals/1.8e/relnotes/LISTSERV14.5-Release-Notes.html#wasecurityalert x_refsource_CONFIRMPatch
- http://www.ngssoftware.com/advisories/listserv_3.txt x_refsource_MISC
- http://www.securityfocus.com/archive/1/426770/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/16951 vdb-entryx_refsource_BIDPatch
- http://www.vupen.com/english/advisories/2006/0824 vdb-entryx_refsource_VUPEN
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2006-1048 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25168 vdb-entryx_refsource_XF
| Link | Providers | Tags |
|---|---|---|
| http://secunia.com/advisories/19106 | third-party-advisoryx_refsource_SECUNIA | |
| http://securitytracker.com/id?1015722 | vdb-entryx_refsource_SECTRACKPatchVendor Advisory | |
| http://www.kb.cert.org/vuls/id/841132 | third-party-advisoryx_refsource_CERT-VNUS Government Resource | |
| http://www.lsoft.com/manuals/1.8e/relnotes/LISTSERV14.5-Release-Notes.html#wasecurityalert | x_refsource_CONFIRMPatch | |
| http://www.ngssoftware.com/advisories/listserv_3.txt | x_refsource_MISC | |
| http://www.securityfocus.com/archive/1/426770/100/0/threaded | mailing-listx_refsource_BUGTRAQ | |
| http://www.securityfocus.com/bid/16951 | vdb-entryx_refsource_BIDPatch | |
| http://www.vupen.com/english/advisories/2006/0824 | vdb-entryx_refsource_VUPEN | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2006-1048 | Advisory | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/25168 | vdb-entryx_refsource_XF |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 7, 2006
Updated Aug 7, 2024
Reserved Mar 7, 2006
Link CVE-2006-1044
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2006-1048 Assigner mitre
Published Mar 7, 2006
Updated Aug 7, 2024
Exploited since n/a
Link EUVD-2006-1048