vendor:
Anubis
by:
Ulf Harnhammar
7.5
CVSS
HIGH
Buffer Overflow and Format String Vulnerabilities
120,134
CWE
Product Name: Anubis
Affected Version From: 3.6.2000
Affected Version To: 3.9.93
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2004
GNU Anubis Multiple Vulnerabilities
GNU Anubis has been reported prone to multiple buffer overflow and format string vulnerabilities. It has been conjectured that a remote attacker may potentially exploit these vulnerabilities to have arbitrary code executed in the context of the Anubis software. The buffer overflow vulnerabilities exist in the 'auth_ident' function in 'auth.c'. The format string vulnerabilities are reported to affect the 'info' function in 'log.c', the 'anubis_error' function in 'errs.c' and the 'ssl_error' function in 'ssl.c'.
Mitigation:
Upgrade to the latest version of GNU Anubis