CVE-2004-1701: Buffer Overflow
Published Aug 9, 2004
·Updated
Heap-based buffer overflow in the AuthenticationDialogue function in cfservd for Cfengine 2.0.0 to 2.1.7p1 allows remote attackers to execute arbitrary code via a long SAUTH command during RSA authentication.
Affected Software
20 affected components
GNU CFEngine=2.0.0
GNU CFEngine=2.0.1
GNU CFEngine=2.0.2
GNU CFEngine=2.0.3
GNU CFEngine=2.0.4
GNU CFEngine=2.0.5
GNU CFEngine=2.0.5-b1
GNU CFEngine=2.0.5-pre
GNU CFEngine=2.0.5-pre2
GNU CFEngine=2.0.6
GNU CFEngine=2.0.7
GNU CFEngine=2.0.7-p1
GNU CFEngine=2.0.7-p2
GNU CFEngine=2.0.7-p3
GNU CFEngine=2.0.8
GNU CFEngine=2.0.8-p1
GNU CFEngine=2.1.0-a6
GNU CFEngine=2.1.0-a8
GNU CFEngine=2.1.0-a9
GNU CFEngine=2.1.7-p1
Remediation
Patch Available
Patch Available
Patch Available
Event History
Aug 9, 2004
CVE Published
04:00 AM
Feb 21, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1701?
CVE-2004-1701 is classified as a high-severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2004-1701?
To fix CVE-2004-1701, you should upgrade to a version of Cfengine that is 2.1.7p2 or later.
3
What software is affected by CVE-2004-1701?
CVE-2004-1701 affects various versions of GNU Cfengine ranging from 2.0.0 to 2.1.7p1.
4
How does CVE-2004-1701 exploit work?
CVE-2004-1701 exploits a heap-based buffer overflow in the AuthenticationDialogue function using a long SAUTH command.
5
Who discovered CVE-2004-1701?
CVE-2004-1701 was discovered by security researchers, contributing to the awareness of vulnerabilities in network management systems.