CVE-2002-0909
Last modified
CVE-2002-0909 is a vulnerability of currently unknown severity. Multiple buffer overflows in mnews 1.22 and earlier allow (1) a remote NNTP server to execute arbitrary code via long responses, or local users can gain privileges via long command line arguments (2) -f, (3) -n, (4) -D, (5) -M, or (6) -P, or via long environment variables (7) JNAMES or (8) MAILSERVER.. EPSS estimates a 2.77% chance of exploitation in the next 30 days.
Description
Multiple buffer overflows in mnews 1.22 and earlier allow (1) a remote NNTP server to execute arbitrary code via long responses, or local users can gain privileges via long command line arguments (2) -f, (3) -n, (4) -D, (5) -M, or (6) -P, or via long environment variables (7) JNAMES or (8) MAILSERVER.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Matsushita Research | Mnews | <= 1.2.2 |
References
- http://www.iss.net/security_center/static/9226.phpVendor Advisory
- http://www.iss.net/security_center/static/9227.phpVendor Advisory
- http://www.securityfocus.com/bid/4899Vendor Advisory
- http://www.securityfocus.com/bid/4900Vendor Advisory
- http://www.iss.net/security_center/static/9226.phpVendor Advisory
- http://www.iss.net/security_center/static/9227.phpVendor Advisory
- http://www.securityfocus.com/bid/4899Vendor Advisory
- http://www.securityfocus.com/bid/4900Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2002-0909?
How severe is CVE-2002-0909?
How do I fix CVE-2002-0909?
Are you affected by CVE-2002-0909?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
