CVE-2004-0989
Last modified
CVE-2004-0989 is a vulnerability of currently unknown severity. Multiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and possibly other versions, may allow remote attackers to execute arbitrary code via (1) a long FTP URL that is not properly handled by the xmlNanoFTPScanURL function, (2) a long proxy URL containing FTP data that is not properly handled by the xmlNanoFTPScanProxy function, and other overflows related to manipulation of DNS length values, including (3) xmlNanoFTPConnect, (4) xmlNanoHTTPConnectHost, and (5) xmlNanoHTTPConnectHost.. EPSS estimates a 21.69% chance of exploitation in the next 30 days.
Description
Multiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and possibly other versions, may allow remote attackers to execute arbitrary code via (1) a long FTP URL that is not properly handled by the xmlNanoFTPScanURL function, (2) a long proxy URL containing FTP data that is not properly handled by the xmlNanoFTPScanProxy function, and other overflows related to manipulation of DNS length values, including (3) xmlNanoFTPConnect, (4) xmlNanoHTTPConnectHost, and (5) xmlNanoHTTPConnectHost.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Xmlsoft | Libxml | 1.8.17 |
| Xmlsoft | Libxml2 | 2.5.11 |
| Xmlsoft | Libxml2 | 2.6.6 |
| Xmlsoft | Libxml2 | 2.6.7 |
| Xmlsoft | Libxml2 | 2.6.8 |
| Xmlsoft | Libxml2 | 2.6.9 |
| Xmlsoft | Libxml2 | 2.6.11 |
| Xmlsoft | Libxml2 | 2.6.12 |
| Xmlsoft | Libxml2 | 2.6.13 |
| Xmlsoft | Libxml2 | 2.6.14 |
| Xmlstarlet | Command Line Xml Toolkit | 0.9.1 |
| Redhat | Fedora Core | core_2.0 |
| Trustix | Secure Linux | 2.0 |
| Trustix | Secure Linux | 2.1 |
| Ubuntu | Ubuntu Linux | 4.1 |
References
- http://www.securityfocus.com/bid/11526Exploit, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/11526Exploit, Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2004-0989?
How severe is CVE-2004-0989?
How do I fix CVE-2004-0989?
Are you affected by CVE-2004-0989?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
