CVE-2004-1916
EPSS 4.2%
Description
Multiple buffer overflows in LCDProc 0.4.1, and possibly other 0.4.x versions up to 0.4.4, allows remote attackers to execute arbitrary code via (1) a long invalid command to parse_all_client_messages function, or (2) long argv command to test_func_func function.
How to fix CVE-2004-1916
To remediate CVE-2004-1916, upgrade the affected package to a fixed version below.
- Debian/lcdproc—upgrade to 0.4.5 or later
Is CVE-2004-1916 being exploited?
Low — EPSS is 4.2%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 0.4.5