CVE
- Id
- 3449
- CVE No.
- CVE-2001-0636
- Status
- Candidate
- Description
- Buffer overflows in Raytheon SilentRunner allow remote attackers to (1) cause a denial of service in the collector (cle.exe) component of SilentRunner 2.0 via traffic containing long passwords, or (2) execute arbitrary commands via long HTTP queries in the Knowledge Browser component in SilentRunner 2.0 and 2.0.1. NOTE: It is highly likely that this candidate will be split into multiple candidates.
- Phase
- Proposed (20010829)
- Votes
- ACCEPT(3) Cole, Foat, Ziese | MODIFY(1) Frech | NOOP(3) Armstrong, Christey, Wall | RECAST(2) Baker, Bishop
- Comments
- Bishop> please split it into 2 candidates, one for the DoS and one | for the execute part | Frech> XF:silentrunner-collector-popuser-bo(6795) | XF:silentrunner-collector-poppass-bo(6796) | XF:silentrunner-collector-httpurl-bo(6797) | Baker> SPLIT | Christey> Consider adding BID:3150 | Christey> Consider adding BID:3151