7.5
CVSSv2

CVE-2009-0363

Published: 17/02/2009 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple buffer overflows in (a) BarnOwl prior to 1.0.5 and (b) owl 2.1.11 allow remote malicious users to execute arbitrary code via vectors involving (1) a crafted zcrypt message, related to zcrypt.c; (2) a reply command on a message with a Zephyr Cc: list, related to zwrite.c; and unspecified other use of the products.

Vulnerable Product Search on Vulmon Subscribe to Product

barnowl barnowl 1.0.2.1

barnowl barnowl 1.0.3

barnowl barnowl

barnowl barnowl 1.0.0

barnowl barnowl 1.0.4

barnowl barnowl 1.0.2

barnowl barnowl 1.0.1

ktools owl 2.1.11

Vendor Advisories

Debian Bug report logs - #515118 CVE-2009-0363: multiple buffer overflows that can be remotely triggered Package: owl; Maintainer for owl is Mark W Eichin <eichin@thokorg>; Source for owl is src:owl (PTS, buildd, popcon) Reported by: Sam Hartman <hartmans@debianorg> Date: Fri, 13 Feb 2009 17:54:01 UTC Severity: g ...