CVE-2010-2725: Input Validation
Published Aug 4, 2010
·Updated
BarnOwl before 1.6.2 does not check the return code of calls to the (1) ZPending and (2) ZReceiveNotice functions in libzephyr, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors.
Affected Software
21 affected components
BarnOwl BarnOwl<=1.6.1
BarnOwl BarnOwl=1.0.0
BarnOwl BarnOwl=1.0.1
BarnOwl BarnOwl=1.0.2
BarnOwl BarnOwl=1.0.2.1
BarnOwl BarnOwl=1.0.3
BarnOwl BarnOwl=1.0.4
BarnOwl BarnOwl=1.0.4.1
BarnOwl BarnOwl=1.0.5
BarnOwl BarnOwl=1.1
BarnOwl BarnOwl=1.1.1
BarnOwl BarnOwl=1.2
BarnOwl BarnOwl=1.2.1
BarnOwl BarnOwl=1.3
BarnOwl BarnOwl=1.4
BarnOwl BarnOwl=1.4-rc1
BarnOwl BarnOwl=1.5
BarnOwl BarnOwl=1.5-rc1
BarnOwl BarnOwl=1.5-rc2
BarnOwl BarnOwl=1.5.1
BarnOwl BarnOwl=1.6
Event History
Aug 4, 2010
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2010-2725?
CVE-2010-2725 is classified as a high severity vulnerability due to its potential to cause denial of service and execute arbitrary code.
2
How do I fix CVE-2010-2725?
To mitigate CVE-2010-2725, upgrade to BarnOwl version 1.6.2 or later.
3
What causes the vulnerability in CVE-2010-2725?
CVE-2010-2725 is caused by the lack of return code checks in the ZPending and ZReceiveNotice functions.
4
Which versions of BarnOwl are affected by CVE-2010-2725?
All versions of BarnOwl prior to 1.6.2 are affected by CVE-2010-2725.
5
Can CVE-2010-2725 be exploited remotely?
Yes, CVE-2010-2725 can be exploited by remote attackers to cause a denial of service.