CVE-2004-2003: Buffer Overflow
Buffer overflow in the sslprcert function in the SSLway filter (sslway.c) for DeleGate 8.9.2 and earlier allows remote attackers to execute arbitrary code via a certificate with a long (1) subject or (2) issuer name field.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-2003?
CVE-2004-2003 is classified as a high-severity vulnerability due to the potential for remote code execution.
How do I fix CVE-2004-2003?
To fix CVE-2004-2003, upgrade DeleGate to version 8.9.3 or later to mitigate the buffer overflow issue.
What systems are affected by CVE-2004-2003?
CVE-2004-2003 affects DeleGate versions 8.9.2 and earlier, along with several specific earlier versions ranging from 7.7.0 to 8.9.2.
Can CVE-2004-2003 be exploited remotely?
Yes, CVE-2004-2003 can be exploited remotely by attackers sending specially crafted certificates.
What type of vulnerability is CVE-2004-2003?
CVE-2004-2003 is a buffer overflow vulnerability that can result in arbitrary code execution.