SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2006-1044

Multiple buffer overflows in LISTSERV 14.3 and 14.4, including LISTSERV Lite and HPO, with the web archive interface enabled, allow remote attackers to execute arbitrary code via unknown attack vectors related to the WA CGI.

HIGH 7.5EPSS 7.47%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (7.47%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Multiple buffer overflows in LISTSERV 14.3 and 14.4, including LISTSERV Lite and HPO, with the web archive interface enabled, allow remote attackers to execute arbitrary code via unknown attack vectors related to the WA CGI. NOTE: technical details will be released after the grace period has ended on 20060603.

CVSS 2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
7.47% probability · 94th percentile
CISA KEV
Not listed
Affected
lsoft/listserv
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.