CVE-2008-2928

Severity
10.0CRITICAL
EPSS
19.1%
top 4.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 29
Latest updateMay 1

Description

Multiple buffer overflows in the adminutil library in CGI applications in Red Hat Directory Server 7.1 before SP7 allow remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted Accept-Language HTTP header.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-fprm-74q4-pj4w: Multiple buffer overflows in the adminutil library in CGI applications in Red Hat Directory Server 72022-05-01
CVEList
CVE-2008-2928: Multiple buffer overflows in the adminutil library in CGI applications in Red Hat Directory Server 72008-08-29

📋Vendor Advisories

1
Red Hat
Server: CGI accept language buffer overflow2007-12-06

💬Community

1
Bugzilla
CVE-2008-2928 Directory Server: CGI accept language buffer overflow2008-07-03
CVE-2008-2928 (CRITICAL CVSS 10) | Multiple buffer overflows in the ad | cvebase.io