10
CVSSv2

CVE-2002-1215

Published: 28/10/2002 Updated: 10/09/2008
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Multiple format string vulnerabilities in heartbeat 0.4.9 and previous versions (claimed as buffer overflows in some sources) allow remote malicious users to execute arbitrary code via certain packets to UDP port 694 (incorrectly claimed as TCP in some sources).

Vulnerable Product Search on Vulmon Subscribe to Product

linux-ha heartbeat

Vendor Advisories

Nathan Wallwork discovered a buffer overflow in heartbeat, a subsystem for High-Availability Linux A remote attacker could send a specially crafted UDP packet that overflows a buffer, leaving heartbeat to execute arbitrary code as root This problem has been fixed in version 0490l-72 for the current stable distribution (woody) and version 04 ...