CVE-2004-0110: Buffer Overflow
Published Mar 4, 2004
·Updated
Buffer overflow in the (1) nanohttp or (2) nanoftp modules in XMLSoft Libxml 2 (Libxml2) 2.6.0 through 2.6.5 allow remote attackers to execute arbitrary code via a long URL.
Affected Software
14 affected components
SGI ProPack=2.3
SGI ProPack=2.4
XMLSoft Libxml=1.8.17
XMLSoft Libxml2=2.4.19
XMLSoft Libxml2=2.4.23
XMLSoft Libxml2=2.5.4
XMLSoft Libxml2=2.5.10
XMLSoft Libxml2=2.5.11
XMLSoft Libxml2=2.6.0
XMLSoft Libxml2=2.6.1
XMLSoft Libxml2=2.6.2
XMLSoft Libxml2=2.6.3
XMLSoft Libxml2=2.6.4
XMLSoft Libxml2=2.6.5
Remediation
Patch Available
Patch Available
Event History
Mar 4, 2004
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0110?
CVE-2004-0110 has been assigned a moderate severity level due to the potential for remote code execution.
2
How do I fix CVE-2004-0110?
To fix CVE-2004-0110, upgrade the affected Libxml2 libraries to versions 2.6.6 or higher.
3
Which versions are affected by CVE-2004-0110?
CVE-2004-0110 affects Libxml2 versions from 2.6.0 to 2.6.5.
4
Can CVE-2004-0110 be exploited remotely?
Yes, CVE-2004-0110 can be exploited by remote attackers via a crafted long URL.
5
What components are vulnerable under CVE-2004-0110?
The vulnerable components under CVE-2004-0110 are the nanohttp and nanoftp modules of Libxml2.