CVE-2005-3354: Buffer Overflow
Published Nov 20, 2005
·Updated
Stack-based buffer overflow in the ldifgetline function in ldif.c of Sylpheed before 2.1.6 allows user-assisted attackers to execute arbitrary code by having local users import LDIF files with long lines.
Affected Software
25 affected components
Sylpheed Sylpheed=0.8.11
Sylpheed Sylpheed=0.9.4
Sylpheed Sylpheed=0.9.5
Sylpheed Sylpheed=0.9.6
Sylpheed Sylpheed=0.9.7
Sylpheed Sylpheed=0.9.8
Sylpheed Sylpheed=0.9.9
Sylpheed Sylpheed=0.9.10
Sylpheed Sylpheed=0.9.11
Sylpheed Sylpheed=0.9.12
Sylpheed Sylpheed=1.0.0
Sylpheed Sylpheed=1.0.1
Sylpheed Sylpheed=1.0.2
Sylpheed Sylpheed=1.0.3
Sylpheed Sylpheed=1.0.4
Sylpheed Sylpheed=2.0
Sylpheed Sylpheed=2.0.1
Sylpheed Sylpheed=2.0.2
Sylpheed Sylpheed=2.0.3
Sylpheed Sylpheed=2.1
Sylpheed Sylpheed=2.1.1
Sylpheed Sylpheed=2.1.2
Sylpheed Sylpheed=2.1.3
Sylpheed Sylpheed=2.1.4
Sylpheed Sylpheed=2.1.5
Remediation
Patch Available
Event History
Nov 20, 2005
CVE Published
09:03 PM
Nov 21, 2005
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-3354?
CVE-2005-3354 is considered to have a high severity due to the potential for arbitrary code execution.
2
How do I fix CVE-2005-3354?
To fix CVE-2005-3354, upgrade to Sylpheed version 2.1.6 or later, which addresses this vulnerability.
3
What kind of vulnerability is CVE-2005-3354?
CVE-2005-3354 is a stack-based buffer overflow vulnerability.
4
Which versions of Sylpheed are affected by CVE-2005-3354?
CVE-2005-3354 affects multiple versions of Sylpheed including versions from 0.8.11 to 2.1.5.
5
Can CVE-2005-3354 be exploited remotely?
CVE-2005-3354 requires user interaction to exploit, as it involves importing malicious LDIF files locally.