7.5
CVSSv2

CVE-2005-2665

Published: 23/08/2005 Updated: 18/10/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Stack-based buffer overflow in expires.c in Elm 2.5 PL5 through PL7, and possibly other versions, allows remote malicious users to execute arbitrary code via an e-mail message with a long Expires header.

Vulnerable Product Search on Vulmon Subscribe to Product

elm development group elm 2.5_pl5

elm development group elm 2.5_pl6

elm development group elm 2.5_pl7

Vendor Advisories

Synopsis elm security update Type/Severity Security Advisory: Critical Topic An updated elm package is now available that fixes a buffer overflow issuefor Red Hat Enterprise Linux 21 AS and AWThis update has been rated as having critical security impact by the RedHat Security Response Team Descr ...

Exploits

/* Exploit code for the bug posted by Ulf Harnhammar (metaurteliacom) archivesneohapsiscom/archives/fulldisclosure/2005-08/0688html Probably you will need to change SYSLOC and STRLOC to work on your box */ #include <stdioh> #include <stdlibh> #include <stringh> #include <unistdh> #define BUFFER 83 ...