CVE Vulnerabilities

CVE-2007-1371

Published: Mar 10, 2007 | Modified: Oct 16, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.9 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

Multiple buffer overflows in Conquest 8.2a and earlier (1) allow local users to gain privileges by querying a metaserver that sends a long server entry processed by metaGetServerList and allow remote metaservers to execute arbitrary code via a long server entry processed by metaGetServerList; (2) allow attackers to have an unknown impact by exceeding the configured number of metaservers; and allow remote attackers to corrupt memory via a SP_CLIENTSTAT packet with certain values of (3) unum or (4) snum, different vulnerabilities than CVE-2003-0933.

Affected Software

Name Vendor Start Version End Version
Conquest Radscan * 8.2a (including)
Conquest Ubuntu dapper *
Conquest Ubuntu devel *
Conquest Ubuntu edgy *
Conquest Ubuntu feisty *
Conquest Ubuntu gutsy *
Conquest Ubuntu hardy *
Conquest Ubuntu intrepid *
Conquest Ubuntu jaunty *
Conquest Ubuntu karmic *
Conquest Ubuntu upstream *

References