Lucene search

K
ubuntucveUbuntu.comUB:CVE-2004-0989
HistoryMar 01, 2005 - 12:00 a.m.

CVE-2004-0989

2005-03-0100:00:00
ubuntu.com
ubuntu.com
15

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

0.134 Low

EPSS

Percentile

95.6%

Multiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and
possibly other versions, may allow remote attackers to execute arbitrary
code via (1) a long FTP URL that is not properly handled by the
xmlNanoFTPScanURL function, (2) a long proxy URL containing FTP data that
is not properly handled by the xmlNanoFTPScanProxy function, and other
overflows related to manipulation of DNS length values, including (3)
xmlNanoFTPConnect, (4) xmlNanoHTTPConnectHost, and (5)
xmlNanoHTTPConnectHost.

OSVersionArchitecturePackageVersionFilename
ubuntu6.06noarchlibxml< 1.8.17-12UNKNOWN
ubuntu6.10noarchlibxml< 1.8.17-12UNKNOWN
ubuntu7.04noarchlibxml< 1.8.17-12UNKNOWN
ubuntu6.06noarchlibxml2< 2.6.24.dfsg-1ubuntu1UNKNOWN
ubuntu6.10noarchlibxml2< 2.6.24.dfsg-1ubuntu1UNKNOWN
ubuntu7.04noarchlibxml2< 2.6.24.dfsg-1ubuntu1UNKNOWN

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

0.134 Low

EPSS

Percentile

95.6%