CVE-2005-2772: Buffer Overflow
Multiple stack-based buffer overflows in University of Minnesota gopher client 3.0.9 allow remote malicious servers to execute arbitrary code via (1) a long "+VIEWS:" reply, which is not properly handled in the VIfromLine function, and (2) certain arguments when launching third party programs such as a web browser from a web link, which is not properly handled in the FIOgetargv function.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2005-2772?
CVE-2005-2772 has a high severity rating due to its potential for remote code execution.
How do I fix CVE-2005-2772?
To mitigate CVE-2005-2772, upgrade the University of Minnesota gopher client to version 3.0.10 or later.
What type of vulnerability is CVE-2005-2772?
CVE-2005-2772 is classified as a stack-based buffer overflow vulnerability.
Which versions of software are affected by CVE-2005-2772?
CVE-2005-2772 specifically affects version 3.0.9 of the University of Minnesota gopher client.
What can attackers do with CVE-2005-2772?
Attackers can exploit CVE-2005-2772 to execute arbitrary code on affected systems.