Lucene search

K
freebsdFreeBSDCA9CE879-5EBB-11D9-A01C-0050569F0001
HistoryJan 05, 2005 - 12:00 a.m.

exim -- two buffer overflow vulnerabilities

2005-01-0500:00:00
vuxml.freebsd.org
19

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

EPSS

0.002

Percentile

56.3%

  1. The function host_aton() can overflow a buffer
    if it is presented with an illegal IPv6 address
    that has more than 8 components.
  2. The second report described a buffer overflow
    in the function spa_base64_to_bits(), which is part
    of the code for SPA authentication.

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

EPSS

0.002

Percentile

56.3%