7.5
CVSSv2

CVE-2003-0805

Published: 06/10/2003 Updated: 18/10/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 760
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple buffer overflows in UMN gopher daemon (gopherd) 2.x and 3.x prior to 3.0.6 allows malicious users to execute arbitrary code via (1) a long filename as a result of a LIST command, and (2) the GSisText function, which calculates the view-type.

Vulnerable Product Search on Vulmon Subscribe to Product

university of minnesota gopherd 3.0.2

university of minnesota gopherd 3.0.3

university of minnesota gopherd 2.3

university of minnesota gopherd 2.3.1

university of minnesota gopherd 2.0.3

university of minnesota gopherd 2.0.4

university of minnesota gopherd 3.0.4

university of minnesota gopherd 3.0.5

university of minnesota gopherd 3.0.0

university of minnesota gopherd 3.0.1

Vendor Advisories

gopherd, a gopher server from the University of Minnesota, contains a number of buffer overflows which could be exploited by a remote attacker to execute arbitrary code with the privileges of the gopherd process (the "gopher" user by default) For the stable distribution (woody) this problem has been fixed in version 303woody1 This program has b ...

Exploits

source: wwwsecurityfocuscom/bid/8168/info It has been reported that there is a buffer overflow condition present in gopherd that may be exploited remotely to execute arbitrary code The affected component is said to be used for determining view-types for gopher objects /*[ UMN gopherd[2xx/3xx]: remote GSisText()/view buffer overflo ...
source: wwwsecurityfocuscom/bid/8167/info It has been reported that the FTP gateway component within the gopherd server is prone to a buffer overflow vulnerability This vulnerability may be present due to a failure to perform bounds checking when processing long filenames returned from the FTP LIST command This could permit code executi ...