CVE-2004-0353: Buffer Overflow
Published Mar 18, 2004
·Updated
Multiple buffer overflows in authident() function in auth.c for GNU Anubis 3.6.0 through 3.6.2, 3.9.92 and 3.9.93 allow remote attackers to gain privileges via a long string.
Affected Software
5 affected components
GNU Anubis=3.9.92
GNU Anubis=3.9.93
GNU Anubis=3.6.0
GNU Anubis=3.6.1
GNU Anubis=3.6.2
Remediation
Patch Available
Event History
Mar 18, 2004
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0353?
CVE-2004-0353 is classified as a high severity vulnerability due to the potential for remote privilege escalation.
2
How do I fix CVE-2004-0353?
To fix CVE-2004-0353, update to a patched version of GNU Anubis that addresses the buffer overflow issues.
3
What versions of GNU Anubis are affected by CVE-2004-0353?
GNU Anubis versions 3.6.0 through 3.6.2, and 3.9.92 and 3.9.93 are affected by CVE-2004-0353.
4
What kind of attack is possible with CVE-2004-0353?
CVE-2004-0353 allows remote attackers to execute code with elevated privileges via a long input string in the auth_ident() function.
5
Is CVE-2004-0353 easy to exploit?
Yes, exploiting CVE-2004-0353 is considered relatively easy for attackers due to its reliance on a simple buffer overflow.