CVE-2008-4631
Last modified
CVE-2008-4631 is a vulnerability of currently unknown severity. Stack-based buffer overflow in the Message::AddToString function in message/Message.cpp in MUSCLE before 4.40 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted message. NOTE: some of these details are obtained from third party information.. EPSS estimates a 4.76% chance of exploitation in the next 30 days.
Description
Stack-based buffer overflow in the Message::AddToString function in message/Message.cpp in MUSCLE before 4.40 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted message. NOTE: some of these details are obtained from third party information.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Myer Sound Laboratories | Muscle | <= 4.30 |
| Myer Sound Laboratories | Muscle | 1.00 |
| Myer Sound Laboratories | Muscle | 1.01 |
| Myer Sound Laboratories | Muscle | 1.10 |
| Myer Sound Laboratories | Muscle | 1.20 |
| Myer Sound Laboratories | Muscle | 1.21 |
| Myer Sound Laboratories | Muscle | 1.22 |
| Myer Sound Laboratories | Muscle | 1.23 |
| Myer Sound Laboratories | Muscle | 1.24 |
| Myer Sound Laboratories | Muscle | 1.30 |
| Myer Sound Laboratories | Muscle | 1.31 |
| Myer Sound Laboratories | Muscle | 1.40 |
| Myer Sound Laboratories | Muscle | 1.41 |
| Myer Sound Laboratories | Muscle | 1.42 |
| Myer Sound Laboratories | Muscle | 1.43 |
| Myer Sound Laboratories | Muscle | 1.44 |
| Myer Sound Laboratories | Muscle | 1.45 |
| Myer Sound Laboratories | Muscle | 1.50 |
| Myer Sound Laboratories | Muscle | 1.51 |
| Myer Sound Laboratories | Muscle | 1.60 |
| Myer Sound Laboratories | Muscle | 1.61 |
| Myer Sound Laboratories | Muscle | 1.62 |
| Myer Sound Laboratories | Muscle | 1.63 |
| Myer Sound Laboratories | Muscle | 1.64 |
| Myer Sound Laboratories | Muscle | 1.70 |
| Myer Sound Laboratories | Muscle | 1.71 |
| Myer Sound Laboratories | Muscle | 1.72 |
| Myer Sound Laboratories | Muscle | 1.80 |
| Myer Sound Laboratories | Muscle | 1.82 |
| Myer Sound Laboratories | Muscle | 1.83 |
| Myer Sound Laboratories | Muscle | 1.84 |
| Myer Sound Laboratories | Muscle | 1.90 |
| Myer Sound Laboratories | Muscle | 1.91 |
| Myer Sound Laboratories | Muscle | 1.92 |
| Myer Sound Laboratories | Muscle | 1.93 |
| Myer Sound Laboratories | Muscle | 2.00 |
| Myer Sound Laboratories | Muscle | 2.10 |
| Myer Sound Laboratories | Muscle | 2.11 |
| Myer Sound Laboratories | Muscle | 2.12 |
| Myer Sound Laboratories | Muscle | 2.13 |
| Myer Sound Laboratories | Muscle | 2.14 |
| Myer Sound Laboratories | Muscle | 2.15 |
| Myer Sound Laboratories | Muscle | 2.16 |
| Myer Sound Laboratories | Muscle | 2.17 |
| Myer Sound Laboratories | Muscle | 2.18 |
| Myer Sound Laboratories | Muscle | 2.19 |
| Myer Sound Laboratories | Muscle | 2.20 |
| Myer Sound Laboratories | Muscle | 2.21 |
| Myer Sound Laboratories | Muscle | 2.23 |
| Myer Sound Laboratories | Muscle | 2.24 |
Showing 50 of 98 affected configurations. See NVD for the full list.
References
- http://secunia.com/advisories/32318Vendor Advisory
- http://secunia.com/advisories/32318Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-4631?
How severe is CVE-2008-4631?
How do I fix CVE-2008-4631?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2008
- CVE-2008-4625SQL injection vulnerability in stnl_iframe.php in the ShiftT…
- CVE-2008-4626Directory traversal vulnerability in index.php in Fritz Berg…
- CVE-2008-4627SQL injection vulnerability in the rGallery plugin 1.09 for …
- CVE-2008-4628SQL injection vulnerability in del.php in myWebland miniBlog…
- CVE-2008-4629Cross-site scripting (XSS) vulnerability in Usagi Project My…
- CVE-2008-4630Multiple unspecified vulnerabilities in Midgard Components (…
- CVE-2008-4632Multiple directory traversal vulnerabilities in index.php in…
- CVE-2008-4633SQL injection vulnerability in Node Vote 5.x before 5.x-1.1 …
- CVE-2008-4634Cross-site scripting (XSS) vulnerability in Movable Type 4 t…
- CVE-2008-4635Unspecified vulnerability in Hisanaga Electric Co, Ltd. hisa…
- CVE-2008-4636yast2-backup 2.14.2 through 2.16.6 on SUSE Linux and Novell …
- CVE-2008-4637Cross-site scripting (XSS) vulnerability in cpCommerce befor…
Are you affected by CVE-2008-4631?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
