CVE-2011-5280: Buffer Overflow
Published Jun 2, 2014
·Updated
Multiple stack-based buffer overflows in BOINC 6.13.x allow remote attackers to cause a denial of service (crash) via a long trickle-up to (1) client/cstrickle.cpp or (2) db/dbbase.cpp.
Affected Software
4 affected components
Rom Walton Boinc=6.13.0
Rom Walton Boinc=6.13.1
Universityofcalifornia Boinc Client=6.13.0
Universityofcalifornia Boinc Client=6.13.1
Remediation
Event History
Jun 2, 2014
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:55 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2011-5280?
CVE-2011-5280 is classified as a medium severity vulnerability due to potential denial of service risks.
2
How do I fix CVE-2011-5280?
To fix CVE-2011-5280, upgrade BOINC to version 6.13.2 or later to address the stack-based buffer overflow issues.
3
What are the potential impacts of CVE-2011-5280?
The potential impact of CVE-2011-5280 includes crashing the application and loss of service availability.
4
Which versions of BOINC are affected by CVE-2011-5280?
CVE-2011-5280 affects BOINC versions 6.13.0 and 6.13.1.
5
Who can exploit CVE-2011-5280?
Remote attackers can exploit CVE-2011-5280 by sending specially crafted long trickle-up messages.