Lucene search

K
cveMitreCVE-2009-0650
HistoryFeb 20, 2009 - 6:30 p.m.

CVE-2009-0650

2009-02-2018:30:00
CWE-119
mitre
web.nvd.nist.gov
29
security
buffer overflow
denial of service
arbitrary code execution
vulnerability
tptest

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

8.2

Confidence

Low

EPSS

0.021

Percentile

89.4%

Stack-based buffer overflow in the GetStatsFromLine function in TPTEST 3.1.7 and earlier, and possibly 5.02, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a STATS line with a long pwd field. NOTE: some of these details are obtained from third party information.

Affected configurations

Nvd
Node
tptesttptestRange3.1.7
OR
tptesttptestMatch5.0.2
VendorProductVersionCPE
tptesttptest*cpe:2.3:a:tptest:tptest:*:*:*:*:*:*:*:*
tptesttptest5.0.2cpe:2.3:a:tptest:tptest:5.0.2:*:*:*:*:*:*:*

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

8.2

Confidence

Low

EPSS

0.021

Percentile

89.4%