CVE-2012-2944
nut - denial of service
EPSS 6.2%
Description
Buffer overflow in the addchar function in common/parseconf.c in upsd in Network UPS Tools (NUT) before 2.6.4 allows remote attackers to execute arbitrary code or cause a denial of service (electric-power outage) via a long string containing non-printable characters.
How to fix CVE-2012-2944
To remediate CVE-2012-2944, upgrade the affected package to a fixed version below.
- Debian/nut—upgrade to 2.6.4-1 or later
- Debian/nut—upgrade to 2.4.3-1.1squeeze2 or later
Is CVE-2012-2944 being exploited?
Moderate — EPSS is 6.2%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (2)
- from 0, < 2.6.4-1
- from 0, < 2.4.3-1.1squeeze2