vendor:
cfengine cfservd
by:
Unknown
7.5
CVSS
HIGH
Remote Heap-Based Buffer Overrun
Unknown
CWE
Product Name: cfengine cfservd
Affected Version From: 2.0.0
Affected Version To: 2.1.7p1
Patch Exists: Unknown
Related CWE: Unknown
CPE: Unknown
Platforms Tested:
Unknown
Remote Heap-Based Buffer Overrun Vulnerability in GNU cfengine cfservd
The GNU cfengine cfservd is prone to a remote heap-based buffer overrun vulnerability. The vulnerability exists in the cfengine cfservd AuthenticationDialogue() function due to a lack of sufficient boundary checks performed on challenge data received from a client. An attacker can exploit this vulnerability to corrupt in-line heap-based memory management data.
Mitigation:
Unknown