CVE
- Id
- 9417
- CVE No.
- CVE-2004-0989
- Status
- Candidate
- Description
- Multiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and possibly other versions, may allow remote attackers to execute arbitrary code via (1) a long FTP URL that is not properly handled by the xmlNanoFTPScanURL function, (2) a long proxy URL containing FTP data that is not properly handled by the xmlNanoFTPScanProxy function, and other overflows related to manipulation of DNS length values, including (3) xmlNanoFTPConnect, (4) xmlNanoHTTPConnectHost, and (5) xmlNanoHTTPConnectHost.
- Phase
- Assigned (20041027)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
62968 | 9417 | CVE-2004-0989 | BUGTRAQ:20041026 libxml2 remote buffer overflows (not in xml parsing code though) | View |
62969 | 9417 | CVE-2004-0989 | URL:http://marc.info/?l=bugtraq&m=109880813013482&w=2 | View |
62970 | 9417 | CVE-2004-0989 | APPLE:APPLE-SA-2005-01-25 | View |
62971 | 9417 | CVE-2004-0989 | URL:http://lists.apple.com/archives/security-announce/2005/Jan/msg00001.html | View |
62972 | 9417 | CVE-2004-0989 | CONECTIVA:CLA-2004:890 | View |
62973 | 9417 | CVE-2004-0989 | URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000890 | View |
62974 | 9417 | CVE-2004-0989 | DEBIAN:DSA-582 | View |
62975 | 9417 | CVE-2004-0989 | URL:http://www.debian.org/security/2004/dsa-582 | View |
62976 | 9417 | CVE-2004-0989 | GENTOO:GLSA-200411-05 | View |
62977 | 9417 | CVE-2004-0989 | URL:http://www.gentoo.org/security/en/glsa/glsa-200411-05.xml | View |
62978 | 9417 | CVE-2004-0989 | REDHAT:RHSA-2004:615 | View |
62979 | 9417 | CVE-2004-0989 | URL:http://www.redhat.com/support/errata/RHSA-2004-615.html | View |
62980 | 9417 | CVE-2004-0989 | REDHAT:RHSA-2004:650 | View |
62981 | 9417 | CVE-2004-0989 | URL:http://www.redhat.com/support/errata/RHSA-2004-650.html | View |
62982 | 9417 | CVE-2004-0989 | SUSE:SUSE-SR:2005:001 | View |
62983 | 9417 | CVE-2004-0989 | URL:http://www.novell.com/linux/security/advisories/2005_01_sr.html | View |
62984 | 9417 | CVE-2004-0989 | UBUNTU:USN-89-1 | View |
62985 | 9417 | CVE-2004-0989 | URL:https://www.ubuntu.com/usn/usn-89-1/ | View |
62986 | 9417 | CVE-2004-0989 | CIAC:P-029 | View |
62987 | 9417 | CVE-2004-0989 | URL:http://www.ciac.org/ciac/bulletins/p-029.shtml | View |
62988 | 9417 | CVE-2004-0989 | BID:11526 | View |
62989 | 9417 | CVE-2004-0989 | URL:http://www.securityfocus.com/bid/11526 | View |
62990 | 9417 | CVE-2004-0989 | OSVDB:11179 | View |
62991 | 9417 | CVE-2004-0989 | URL:http://www.osvdb.org/11179 | View |
62992 | 9417 | CVE-2004-0989 | OSVDB:11180 | View |
62993 | 9417 | CVE-2004-0989 | URL:http://www.osvdb.org/11180 | View |
62994 | 9417 | CVE-2004-0989 | OSVDB:11324 | View |
62995 | 9417 | CVE-2004-0989 | URL:http://www.osvdb.org/11324 | View |
62996 | 9417 | CVE-2004-0989 | OVAL:oval:org.mitre.oval:def:1173 | View |
62997 | 9417 | CVE-2004-0989 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:1173 | View |
62998 | 9417 | CVE-2004-0989 | OVAL:oval:org.mitre.oval:def:10505 | View |
62999 | 9417 | CVE-2004-0989 | URL:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:10505 | View |
63000 | 9417 | CVE-2004-0989 | SECTRACK:1011941 | View |
63001 | 9417 | CVE-2004-0989 | URL:http://securitytracker.com/id?1011941 | View |
63002 | 9417 | CVE-2004-0989 | SECUNIA:13000 | View |
63003 | 9417 | CVE-2004-0989 | URL:http://secunia.com/advisories/13000 | View |
63004 | 9417 | CVE-2004-0989 | XF:libxml2-xmlnanoftpscanurl-bo(17870) | View |
63005 | 9417 | CVE-2004-0989 | URL:http://xforce.iss.net/xforce/xfdb/17870 | View |
63006 | 9417 | CVE-2004-0989 | XF:libxml2-xmlnanoftpscanproxy-bo(17875) | View |
63007 | 9417 | CVE-2004-0989 | URL:http://xforce.iss.net/xforce/xfdb/17875 | View |
63008 | 9417 | CVE-2004-0989 | XF:libxml2-nanoftp-file-bo(17872) | View |
63009 | 9417 | CVE-2004-0989 | URL:http://xforce.iss.net/xforce/xfdb/17872 | View |
63010 | 9417 | CVE-2004-0989 | XF:libxml2-nanohttp-file-bo(17876) | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
63121 | JVNDB-2004-000463 | GD ライブラリの不正な PNG ファイルの処理による整数オーバフローの脆弱性 | GD ライブラリには、gd_png.c の gdImageCreateFromPngCtx() 関数において PNG ファイルの処理に不備が存在するため、意図的に作成された PNG ファイルを処理した場合に整数オーバーフローが発生する脆弱性が存在します。 | CVE-2004-0990 | 9417 | 10 | http://jvndb.jvn.jp/ja/contents/2004/JVNDB-2004-000463.html | View |