CVE-2003-0849: Buffer Overflow
Buffer overflow in net.c for cfengine 2.x before 2.0.8 allows remote attackers to execute arbitrary code via certain packets with modified length values, which is trusted by the ReceiveTransaction function when using a buffer provided by the BusyWithConnection function.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2003-0849?
CVE-2003-0849 is considered to have a critical severity level due to the potential for remote code execution.
How do I fix CVE-2003-0849?
To fix CVE-2003-0849, upgrade cfengine to version 2.0.8 or later, which addresses the buffer overflow vulnerability.
Which versions of GNU CFEngine are affected by CVE-2003-0849?
CVE-2003-0849 affects GNU CFEngine versions 2.0.0 through 2.0.7 and certain earlier versions.
What type of vulnerability is CVE-2003-0849?
CVE-2003-0849 is a buffer overflow vulnerability that can allow remote attackers to execute arbitrary code.
Can CVE-2003-0849 be exploited remotely?
Yes, CVE-2003-0849 can be exploited remotely via specially crafted packets.