First published: Tue Jun 11 2002(Updated: )
Buffer overflow in (1) lprintf and (2) cprintf in sysdep.c of Citadel/UX 5.90 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via attacks such as a long HELO command to the SMTP server.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Citadel | <=5.90 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0432 is classified as a high severity vulnerability due to its potential to cause denial of service and arbitrary code execution.
To mitigate CVE-2002-0432, upgrade to a version of Citadel/UX later than 5.90 that addresses this buffer overflow issue.
CVE-2002-0432 affects the lprintf and cprintf functions in sysdep.c.
CVE-2002-0432 can lead to system crashes or allow remote attackers to execute arbitrary code.
Citadel/UX versions 5.90 and earlier are vulnerable to CVE-2002-0432.