CVE-2004-2461: Buffer Overflow
Published Dec 31, 2004
·Updated
Buffer overflow in pop3.c in gnubiff before 2.0.0 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code.
Affected Software
10 affected components
GNU gnubiff=1.2.0
GNU gnubiff=1.0.6
GNU gnubiff=1.0.7
GNU gnubiff=1.0.5
GNU gnubiff=1.0.3
GNU gnubiff=1.4.0
GNU gnubiff=1.0.10
GNU gnubiff=1.0.9
GNU gnubiff=1.0.8
GNU gnubiff=1.0.4
Remediation
Patch Available
Patch Available
Event History
Dec 31, 2004
CVE Published
05:00 AM
Aug 20, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-2461?
CVE-2004-2461 is classified as a high-severity vulnerability due to its potential to cause denial of service and execute arbitrary code.
2
How do I fix CVE-2004-2461?
To address CVE-2004-2461, upgrade to Gnubiff version 2.0.0 or later.
3
What systems are affected by CVE-2004-2461?
CVE-2004-2461 affects multiple versions of Gnubiff, specifically versions 1.0.3 through 1.4.0.
4
What type of vulnerability is CVE-2004-2461?
CVE-2004-2461 is a buffer overflow vulnerability which can lead to crashes or arbitrary code execution.
5
Can CVE-2004-2461 be exploited remotely?
Yes, CVE-2004-2461 can be exploited remotely, allowing attackers to crash the service or potentially execute malicious code.