CVE-2004-1289
pcal - buffer overflows
EPSS 14.7%
Description
Multiple buffer overflows in (1) the getline function in pcalutil.c and (2) the get_holiday function in readfile.c for pcal 4.7.1 allow remote attackers to execute arbitrary code via a crafted calendar file.
How to fix CVE-2004-1289
To remediate CVE-2004-1289, upgrade the affected package to a fixed version below.
- Debian/pcal—upgrade to 4.8.0-1 or later
- Debian/pcal—upgrade to 4.7-8woody1 or later
Is CVE-2004-1289 being exploited?
Moderate — EPSS is 14.7%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (2)
- from 0, < 4.8.0-1
- from 0, < 4.7-8woody1