CVE-2003-1441: Input Validation
Published Dec 31, 2003
·Updated
Posadis 0.50.4 through 0.50.8 allows remote attackers to cause a denial of service (crash) via a DNS message without a question section, which triggers null dereference.
Affected Software
5 affected components
Posadis Posadis=0.50.4
Posadis Posadis=0.50.5
Posadis Posadis=0.50.6
Posadis Posadis=0.50.7
Posadis Posadis=0.50.8
Remediation
Patch Available
Event History
Dec 31, 2003
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityWeaknessAffected Software
Oct 23, 2007
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2003-1441?
CVE-2003-1441 is classified as a denial of service vulnerability.
2
How do I fix CVE-2003-1441?
To fix CVE-2003-1441, update to a version of Posadis later than 0.50.8.
3
Which versions of Posadis are affected by CVE-2003-1441?
CVE-2003-1441 affects Posadis versions 0.50.4 through 0.50.8.
4
What type of attack does CVE-2003-1441 enable?
CVE-2003-1441 enables remote attackers to cause a crash through a malformed DNS message.
5
Is CVE-2003-1441 easily exploitable?
Yes, CVE-2003-1441 can be exploited remotely with a specific DNS message format.