CVE-2005-2772
gopher - buffer overflows
EPSS 10.0%
描述
Multiple stack-based buffer overflows in University of Minnesota gopher client 3.0.9 allow remote malicious servers to execute arbitrary code via (1) a long "+VIEWS:" reply, which is not properly handled in the VIfromLine function, and (2) certain arguments when launching third party programs such as a web browser from a web link, which is not properly handled in the FIOgetargv function.
如何修補 CVE-2005-2772
要修補 CVE-2005-2772,請將受影響套件升級到下列已修補版本。
- Debian/gopher—升級至 3.0.11 或更新版本
- Debian/gopher—升級至 3.0.3woody4 或更新版本
CVE-2005-2772 正在被利用嗎?
中等 — EPSS 為 10.0%,可持續追蹤但非最高優先。
受影響套件(2)
- from 0, < 3.0.11
- from 0, < 3.0.3woody4