10
CVSSv2

CVE-2000-0743

Published: 20/10/2000 Updated: 05/09/2008
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Buffer overflow in University of Minnesota (UMN) gopherd 2.x allows remote malicious users to execute arbitrary commands via a DES key generation request (GDESkey) that contains a long ticket value.

Vulnerable Product Search on Vulmon Subscribe to Product

university of minnesota gopherd 2.3

university of minnesota gopherd 2.3.1

Exploits

source: wwwsecurityfocuscom/bid/1591/info It is possible to either execute arbitrary code or crash a remote system running University of Minnesota's Gopher Daemon, depending on the data entered An unchecked buffer exists in the 'halidate' function of Gopherd, where the 512 byte buffer can be overwritten with approximately 600 bytes of da ...