CVE-2004-0455
published 2004-12-06CVE-2004-0455: Buffer overflow in cgi.c in www-sql before 0.5.7 allows local users to execute arbitrary code via a web page that is processed by www-sql.
PriorityP424high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.52%
41.2th percentile
Buffer overflow in cgi.c in www-sql before 0.5.7 allows local users to execute arbitrary code via a web page that is processed by www-sql.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| www-sql_project | www-sql | < 0.5.7 | 0.5.7 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
HelixPlayer Vuln (CAN-2005-0455)
bugzilla·2005-03-02
[MEDIUM] HelixPlayer Vuln (CAN-2005-0455)
HelixPlayer Vuln (CAN-2005-0455)
RealPlayer is also vulnerable; waiting on final 1.0.3 upstream release.
+++ This bug was initially created as a clone of Bug #150048 +++
Description of problem:
A couple buffer overflows.
http://www.idefense.com/application/poi/display?id=209&type=vulnerabilities
http://service.real.com/help/faq/security/050224_player/EN/
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0455
Version-Release number of selected component (if applicable):
HelixPlayer-1.0.1.gold-6.i386.rpm
Additional info:
HelixPlayer 1.0.2, with fixes for these exploits, is available at:
https://player.helixcommunity.org/2004/downloads/
Discussion:
Looks to me like there's a HelixPlayer erratum now:
https://rhn.redhat.com/errata/RHSA-2005-271.html
Should this bug be closed? (And
Bugzilla
HelixPlayer Vuln (CAN-2005-0455)
bugzilla·2005-03-01
[MEDIUM] HelixPlayer Vuln (CAN-2005-0455)
HelixPlayer Vuln (CAN-2005-0455)
Description of problem:
A couple buffer overflows.
http://www.idefense.com/application/poi/display?id=209&type=vulnerabilities
http://service.real.com/help/faq/security/050224_player/EN/
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2005-0455
Version-Release number of selected component (if applicable):
HelixPlayer-1.0.1.gold-6.i386.rpm
Additional info:
HelixPlayer 1.0.2, with fixes for these exploits, is available at:
https://player.helixcommunity.org/2004/downloads/
Discussion:
As far as I know 1.0.2 does not fix the issues; they are solved in a pending
1.0.3. Once that appears I'll upload it.
---
This was fixed in an FC3 update. Closing...
2004-12-06
Published