CVE-2004-2460: Medium severity GNU gnubiff vulnerability
Published Dec 31, 2004
·Updated
Unknown vulnerability in POP3 in gnubiff before 2.0.0 allows remote attackers to cause a denial of service (application crash) via an "infinite" Unique IDentification Listing (UIDL) list.
Affected Software
10 affected components
GNU gnubiff=1.2.0
GNU gnubiff=1.0.6
GNU gnubiff=1.0.7
GNU gnubiff=1.0.5
GNU gnubiff=1.0.3
GNU gnubiff=1.4.0
GNU gnubiff=1.0.10
GNU gnubiff=1.0.9
GNU gnubiff=1.0.8
GNU gnubiff=1.0.4
Remediation
Patch Available
Patch Available
Event History
Dec 31, 2004
CVE Published
05:00 AM
Aug 20, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-2460?
The severity of CVE-2004-2460 is categorized as a denial of service vulnerability due to application crashes.
2
How do I fix CVE-2004-2460?
To fix CVE-2004-2460, upgrade to gnubiff version 2.0.0 or later where the vulnerability has been addressed.
3
What software versions are affected by CVE-2004-2460?
CVE-2004-2460 affects gnubiff versions 1.0.3 through 1.4.0, including various earlier versions.
4
Can CVE-2004-2460 be exploited remotely?
Yes, CVE-2004-2460 can be exploited remotely to cause a denial of service condition.
5
What is the impact of CVE-2004-2460 on systems using gnubiff?
The impact of CVE-2004-2460 on systems using gnubiff is an application crash leading to service unavailability.