5
CVSSv2

CVE-2004-1702

Published: 09/08/2004 Updated: 11/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The AuthenticationDialogue function in cfservd for Cfengine 2.0.0 to 2.1.7p1 does not properly check the return value of the ReceiveTransaction function, which leads to a failed malloc call and triggers to a null dereference, which allows remote malicious users to cause a denial of service (crash).

Vulnerable Product Search on Vulmon Subscribe to Product

gnu cfengine 2.0.3

gnu cfengine 2.0.4

gnu cfengine 2.0.7

gnu cfengine 2.0.0

gnu cfengine 2.0.5

gnu cfengine 2.1.0

gnu cfengine 2.0.1

gnu cfengine 2.0.2

gnu cfengine 2.0.6

gnu cfengine 2.1.7

gnu cfengine 2.0.8