CVE-2004-1482: High severity BNC BNC vulnerability
Published Dec 31, 2004
·Updated
The sbufgetmsg function in BNC incorrectly handles backspace characters, which could allow remote attackers to bypass authentication and gain access to arbitrary scripts.
Affected Software
6 affected components
BNC BNC=2.2.4
BNC BNC=2.4.6
BNC BNC=2.4.8
BNC BNC=2.6
BNC BNC=2.6.2
BNC BNC=2.8.8
Remediation
Patch Available
Patch Available
Patch Available
Event History
Dec 31, 2004
CVE Published
05:00 AM
Feb 13, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1482?
CVE-2004-1482 is considered a medium severity vulnerability that could allow remote authentication bypass.
2
How do I fix CVE-2004-1482?
To fix CVE-2004-1482, upgrade BNC to version 2.8.9 or later, which addresses the vulnerability.
3
Which versions of BNC are affected by CVE-2004-1482?
CVE-2004-1482 affects BNC versions 2.2.4, 2.4.6, 2.4.8, 2.6, 2.6.2, and 2.8.8.
4
What type of attack does CVE-2004-1482 enable?
CVE-2004-1482 enables remote attackers to bypass authentication and potentially access arbitrary scripts.
5
Is there a permanent solution for CVE-2004-1482?
Yes, the permanent solution for CVE-2004-1482 is to upgrade to versions of BNC that are not vulnerable, specifically version 2.8.9 or newer.