CVE-2006-1044
Multiple buffer overflows in LISTSERV 14.3 and 14.4, including LISTSERV Lite and HPO, with the web archive interface enabled, allow remote attackers to execute arbitrary code via unknown attack vectors related to the WA CGI.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (7.47%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple buffer overflows in LISTSERV 14.3 and 14.4, including LISTSERV Lite and HPO, with the web archive interface enabled, allow remote attackers to execute arbitrary code via unknown attack vectors related to the WA CGI. NOTE: technical details will be released after the grace period has ended on 20060603.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 7.47% probability · 94th percentile
- CISA KEV
- Not listed
- Affected
- lsoft/listserv
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/19106
- http://securitytracker.com/id?1015722Patch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/841132US Government Resource
- http://www.lsoft.com/manuals/1.8e/relnotes/LISTSERV14.5-Release-Notes.html#wasecurityalertPatch
- http://www.ngssoftware.com/advisories/listserv_3.txt
- http://www.securityfocus.com/archive/1/426770/100/0/threaded
- http://www.securityfocus.com/bid/16951Patch
- http://www.vupen.com/english/advisories/2006/0824
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25168
- http://secunia.com/advisories/19106
- http://securitytracker.com/id?1015722Patch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/841132US Government Resource
- http://www.lsoft.com/manuals/1.8e/relnotes/LISTSERV14.5-Release-Notes.html#wasecurityalertPatch
- http://www.ngssoftware.com/advisories/listserv_3.txt
- http://www.securityfocus.com/archive/1/426770/100/0/threaded
- http://www.securityfocus.com/bid/16951Patch
- http://www.vupen.com/english/advisories/2006/0824
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25168
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.