CVE-2005-2772

Multiple stack-based buffer overflows in University of Minnesota gopher client 3.0.9 allow remote malicious servers to execute arbitrary code via (1) a long "+VIEWS:" reply, which is not properly handled in the VIfromLine function, and (2) certain arguments when launching third party programs such as a web browser from a web link, which is not properly handled in the FIOgetargv function.
Configurations

Configuration 1 (hide)

cpe:2.3:a:university_of_minnesota:gopher:3.0.9:*:*:*:*:*:*:*

History

21 Nov 2024, 00:00

Type Values Removed Values Added
References () http://marc.info/?l=bugtraq&m=112559902931614&w=2 - () http://marc.info/?l=bugtraq&m=112559902931614&w=2 -
References () http://secunia.com/advisories/16614/ - () http://secunia.com/advisories/16614/ -
References () http://secunia.com/advisories/17016 - () http://secunia.com/advisories/17016 -
References () http://www.debian.org/security/2005/dsa-832 - () http://www.debian.org/security/2005/dsa-832 -
References () http://www.kb.cert.org/vuls/id/619812 - Third Party Advisory, US Government Resource () http://www.kb.cert.org/vuls/id/619812 - Third Party Advisory, US Government Resource
References () http://www.securityfocus.com/bid/14693 - Exploit () http://www.securityfocus.com/bid/14693 - Exploit
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/22053 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/22053 -

Information

Published : 2005-09-02 23:03

Updated : 2024-11-21 00:00


NVD link : CVE-2005-2772

Mitre link : CVE-2005-2772

CVE.ORG link : CVE-2005-2772


JSON object : View

Products Affected

university_of_minnesota

  • gopher