Lucene search

K
cveMitreCVE-2006-6685
HistoryDec 21, 2006 - 7:28 p.m.

CVE-2006-6685

2006-12-2119:28:00
CWE-119
mitre
web.nvd.nist.gov
29
cve-2006-6685
buffer overflow
denial of service
arbitrary code execution
security vulnerability
chetcpasswd

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

8

Confidence

High

EPSS

0

Percentile

5.1%

Heap-based buffer overflow in Pedro Lineu Orso chetcpasswd 2.3.3 allows local users to cause a denial of service (application crash) and possibly execute arbitrary code via a long REMOTE_ADDR environment variable. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

Affected configurations

Nvd
Node
pedro_lineu_orsochetcpasswdMatch2.3.3
VendorProductVersionCPE
pedro_lineu_orsochetcpasswd2.3.3cpe:2.3:a:pedro_lineu_orso:chetcpasswd:2.3.3:*:*:*:*:*:*:*

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

8

Confidence

High

EPSS

0

Percentile

5.1%

Related for CVE-2006-6685