10
CVSSv2

CVE-2001-0301

Published: 03/05/2001 Updated: 10/10/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Buffer overflow in Analog prior to 4.16 allows remote malicious users to execute arbitrary commands by using the ALIAS command to construct large strings.

Vulnerable Product Search on Vulmon Subscribe to Product

stephen turner analog

Vendor Advisories

The author of analog, Stephen Turner, has found a buffer overflow bug in all versions of analog except of version 416 A malicious user could use an ALIAS command to construct very long strings which were not checked for length and boundaries This bug is particularly dangerous if the form interface (which allows unknown users to run the program v ...