CVE-2003-0850
published 2003-11-17CVE-2003-0850: The TCP reassembly functionality in libnids before 1.18 allows remote attackers to cause "memory corruption" and possibly execute arbitrary code via "overlarge…
PriorityP431high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
3.68%
88.4th percentile
The TCP reassembly functionality in libnids before 1.18 allows remote attackers to cause "memory corruption" and possibly execute arbitrary code via "overlarge TCP packets."
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libnids | < libnids 1.18-1 (bookworm) | libnids 1.18-1 (bookworm) |
| dug_song | dsniff | — | — |
| libnids_project | libnids | >= 0 < 1.18-1 | 1.18-1 |
| libnids_project | libnids | >= 0 < 1.18-1 | 1.18-1 |
| libnids_project | libnids | >= 0 < 1.18-1 | 1.18-1 |
| libnids_project | libnids | >= 0 < 1.18-1 | 1.18-1 |
| rafal_wojtczuk | libnids | — | — |
| rafal_wojtczuk | libnids | — | — |
| rafal_wojtczuk | libnids | — | — |
| rafal_wojtczuk | libnids | — | — |
| rafal_wojtczuk | libnids | — | — |
| rafal_wojtczuk | libnids | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2003-0850: libnids - The TCP reassembly functionality in libnids before 1.18 allows remote attackers ...
vendor_debian·2003·CVSS 7.5
CVE-2003-0850 [HIGH] CVE-2003-0850: libnids - The TCP reassembly functionality in libnids before 1.18 allows remote attackers ...
The TCP reassembly functionality in libnids before 1.18 allows remote attackers to cause "memory corruption" and possibly execute arbitrary code via "overlarge TCP packets."
Scope: local
bookworm: resolved (fixed in 1.18-1)
bullseye: resolved (fixed in 1.18-1)
forky: resolved (fixed in 1.18-1)
sid: resolved (fixed in 1.18-1)
trixie: resolved (fixed in 1.18-1)
GHSA
GHSA-r5g5-pgp6-x49m: The TCP reassembly functionality in libnids before 1
ghsa_unreviewed·2022-04-29
CVE-2003-0850 [HIGH] GHSA-r5g5-pgp6-x49m: The TCP reassembly functionality in libnids before 1
The TCP reassembly functionality in libnids before 1.18 allows remote attackers to cause "memory corruption" and possibly execute arbitrary code via "overlarge TCP packets."
OSV
CVE-2003-0850: The TCP reassembly functionality in libnids before 1
osv·2003-11-17·CVSS 7.5
CVE-2003-0850 [HIGH] CVE-2003-0850: The TCP reassembly functionality in libnids before 1
The TCP reassembly functionality in libnids before 1.18 allows remote attackers to cause "memory corruption" and possibly execute arbitrary code via "overlarge TCP packets."
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000773http://marc.info/?l=bugtraq&m=106728224210446&w=2http://secunia.com/advisories/10543http://sourceforge.net/project/shownotes.php?release_id=191323http://www.debian.org/security/2004/dsa-410http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000773http://marc.info/?l=bugtraq&m=106728224210446&w=2http://secunia.com/advisories/10543http://sourceforge.net/project/shownotes.php?release_id=191323http://www.debian.org/security/2004/dsa-410
2003-11-17
Published