CVE-2004-0289: Buffer Overflow
Published Mar 18, 2004
·Updated
Buffer overflow in sdbscan in SignatureDB 0.1.1 allows local users to cause a denial of service (segmentation fault) via a database file that contains a large key parameter.
Affected Software
1 affected component
Paul L Daniels Signaturedb=0.1.1
Event History
Mar 18, 2004
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0289?
CVE-2004-0289 has a medium severity rating as it can lead to a denial of service through a buffer overflow.
2
How do I fix CVE-2004-0289?
To fix CVE-2004-0289, upgrade SignatureDB to a version that is not affected by this vulnerability.
3
Who is affected by CVE-2004-0289?
Local users running SignatureDB version 0.1.1 are affected by CVE-2004-0289.
4
What does CVE-2004-0289 exploit?
CVE-2004-0289 exploits a buffer overflow in the sdbscan function of SignatureDB due to large key parameters in the database file.
5
Is CVE-2004-0289 a remote or local vulnerability?
CVE-2004-0289 is a local vulnerability, affecting users with access to the system where SignatureDB is running.