7.2
CVSSv2

CVE-2004-0548

Published: 06/08/2004 Updated: 28/11/2016
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Multiple stack-based buffer overflows in the word-list-compress functionality in compress.c for Aspell allow local users to execute arbitrary code via a long entry in the wordlist that is not properly handled when using the (1) "c" compress option or (2) "d" decompress option.

Vulnerable Product Search on Vulmon Subscribe to Product

gnu aspell 0.50.5

gentoo linux 1.4

Exploits

/* Fuck private exploits Fuck iranian hacking (and security !!) teams who are just some fucking kiddies Fuck all "Security money makers" word-list-compress local exploit - SECU Coded by : c0d3r / root razavi1366[at]yahoo[dot]com word-list-compress is not setuid so good for backdooring gratz fly to : LorD - NT - sIiiS - vbe ...