CVE-2004-1772
published 2004-12-31CVE-2004-1772: Stack-based buffer overflow in shar in GNU sharutils 4.2.1 allows local users to execute arbitrary code via a long -o command line argument.
PriorityP416medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EPSS
0.65%
46.8th percentile
Stack-based buffer overflow in shar in GNU sharutils 4.2.1 allows local users to execute arbitrary code via a long -o command line argument.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | sharutils | < sharutils 1:4.2.1-11 (bookworm) | sharutils 1:4.2.1-11 (bookworm) |
| gnu | sharutils | — | — |
| gnu | sharutils | — | — |
| gnu | sharutils | >= 0 < 1:4.2.1-11 | 1:4.2.1-11 |
| gnu | sharutils | >= 0 < 1:4.2.1-11 | 1:4.2.1-11 |
| gnu | sharutils | >= 0 < 1:4.2.1-11 | 1:4.2.1-11 |
| gnu | sharutils | >= 0 < 1:4.2.1-11 | 1:4.2.1-11 |
CVSS provenance
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv4.6MEDIUM
vendor_debian4.6MEDIUM
vendor_redhat4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
security flaw
vendor_redhat·2004-04-06·CVSS 4.6
CVE-2004-1772 [MEDIUM] security flaw
security flaw
Stack-based buffer overflow in shar in GNU sharutils 4.2.1 allows local users to execute arbitrary code via a long -o command line argument.
Debian
CVE-2004-1772: sharutils - Stack-based buffer overflow in shar in GNU sharutils 4.2.1 allows local users to...
vendor_debian·2004·CVSS 4.6
CVE-2004-1772 [MEDIUM] CVE-2004-1772: sharutils - Stack-based buffer overflow in shar in GNU sharutils 4.2.1 allows local users to...
Stack-based buffer overflow in shar in GNU sharutils 4.2.1 allows local users to execute arbitrary code via a long -o command line argument.
Scope: local
bookworm: resolved (fixed in 1:4.2.1-11)
bullseye: resolved (fixed in 1:4.2.1-11)
forky: resolved (fixed in 1:4.2.1-11)
sid: resolved (fixed in 1:4.2.1-11)
trixie: resolved (fixed in 1:4.2.1-11)
GHSA
GHSA-c6qx-vg4x-8xrp: Stack-based buffer overflow in shar in GNU sharutils 4
ghsa_unreviewed·2022-04-29
CVE-2004-1772 [MEDIUM] GHSA-c6qx-vg4x-8xrp: Stack-based buffer overflow in shar in GNU sharutils 4
Stack-based buffer overflow in shar in GNU sharutils 4.2.1 allows local users to execute arbitrary code via a long -o command line argument.
OSV
CVE-2004-1772: Stack-based buffer overflow in shar in GNU sharutils 4
osv·2004-12-31·CVSS 4.6
CVE-2004-1772 [MEDIUM] CVE-2004-1772: Stack-based buffer overflow in shar in GNU sharutils 4
Stack-based buffer overflow in shar in GNU sharutils 4.2.1 allows local users to execute arbitrary code via a long -o command line argument.
No detection rules found.
No public exploits indexed.
http://marc.info/?l=bugtraq&m=108137386310299&w=2http://www.redhat.com/support/errata/RHSA-2005-377.htmlhttp://www.securityfocus.com/archive/1/359639http://www.securityfocus.com/bid/10066https://bugzilla.fedora.us/show_bug.cgi?id=2155https://exchange.xforce.ibmcloud.com/vulnerabilities/15759https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11722http://marc.info/?l=bugtraq&m=108137386310299&w=2http://www.redhat.com/support/errata/RHSA-2005-377.htmlhttp://www.securityfocus.com/archive/1/359639http://www.securityfocus.com/bid/10066https://bugzilla.fedora.us/show_bug.cgi?id=2155https://exchange.xforce.ibmcloud.com/vulnerabilities/15759https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11722
2004-12-31
Published