Alerts This Week
Warning Icon 1 540
Alerts This Week
Warning Icon 1 540

Gentoo: 200406-22 High: Pavuk Remote Code Execution Threat

gentoo
Calendar Grey June 30, 2004
Dist Gentoo Esm H88
The Gentoo GLSA 200406-24 addresses a critical buffer overrun in the application Avidan, which could permit attackers to execute arbitrary code remotely.
Pavuk contains a bug potentially allowing an attacker to run arbitrary code.

Summary

Gentoo Linux Security Advisory GLSA 200406-22 https://security.gentoo.org/ Severity: High Title: Pavuk: Remote buffer overflow Date: June 30, 2004 ID: 200406-22

Synopsis ======= Pavuk contains a bug potentially allowing an attacker to run arbitrary code.
Background ========= Pavuk is web spider and website mirroring tool.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-misc/pavuk <= 0.9.28-r1 >= 0.9.28-r2
========== When Pavuk connects to a web server and the server sends back the HTTP status code 305 (Use Proxy), Pavuk copies data from the HTTP Location header in an unsafe manner.
Impact ===== An attacker could cause a stack-based buffer overflow which co...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns


Warning: Undefined array key "advisory_info" in /var/www/www.linuxsecurity.com-443/html/tmp/regularlabs/custom_php/3312537_4c9dbbdde36eef04251a4ced7eac4df9 on line 11

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Related News

Your message here