7.5
CVSSv2

CVE-2002-0900

Published: 04/10/2002 Updated: 05/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Buffer overflow in pks PGP public key web server prior to 0.9.5 allows remote malicious users to cause a denial of service (crash) and possibly execute arbitrary code via a long search argument to the lookup capability.

Vulnerable Product Search on Vulmon Subscribe to Product

mit pgp public key server 0.9.2

mit pgp public key server 0.9.4

Exploits

source: wwwsecurityfocuscom/bid/4828/info The PGP Public Key Server is a freely available, open source software package distributed by MIT It is designed for use on Linux and Unix operating systems The PGP Public Key Server does not properly handle long search strings Under some conditions, it may be possible to pass a long string to ...