diff options
author | Josef El-Rayes <josef@FreeBSD.org> | 2004-11-11 22:46:38 +0000 |
---|---|---|
committer | Josef El-Rayes <josef@FreeBSD.org> | 2004-11-11 22:46:38 +0000 |
commit | eecd97c0e748160651aee4b06071a2b94307acf3 (patch) | |
tree | af14531fb03716af45b2c453519ac05b1d98fdbc /security/vuxml/vuln.xml | |
parent | 13af6ab90a2ddb50278b466aa9c83f9416bf2c20 (diff) | |
download | ports-eecd97c0e748160651aee4b06071a2b94307acf3.tar.gz ports-eecd97c0e748160651aee4b06071a2b94307acf3.zip |
Notes
Diffstat (limited to 'security/vuxml/vuln.xml')
-rw-r--r-- | security/vuxml/vuln.xml | 25 |
1 files changed, 25 insertions, 0 deletions
diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index c941c7dfb84a..a739b5fb4acc 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -32,6 +32,31 @@ EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. --> <vuxml xmlns="http://www.vuxml.org/apps/vuxml-1"> + <vuln vid="1f8dea68-3436-11d9-952f-000c6e8f12ef"> + <topic>bnc -- buffer-overflow vulnerability</topic> + <affects> + <package> + <name>bnc</name> + <range><le>2.8.9</le></range> + </package> + </affects> + <description> + <body xmlns="http://www.w3.org/1999/xhtml"> + <p>The function getnickuserhost() suffers from a buffer-overflow. + It is called when BNC processes a response from IRC server. + An attacking server can use this vulnerability to gain shell + access, on the BNC running machine.</p> + </body> + </description> + <references> + <mlist msgid="20041110131046.GA21604@cecilija.zesoi.fer.hr>">http://marc.theaimsgroup.com/?l=bugtraq&m=110011817627839</mlist> + </references> + <dates> + <discovery>2004-10-11</discovery> + <entry>2004-10-11</entry> + </dates> + </vuln> + <vuln vid="027380b7-3404-11d9-ac1b-000d614f7fad"> <topic>hafiye -- lack of terminal escape sequence filtering</topic> <affects> |