Vulnerability Details CVE-2003-0849
Buffer overflow in net.c for cfengine 2.x before 2.0.8 allows remote attackers to execute arbitrary code via certain packets with modified length values, which is trusted by the ReceiveTransaction function when using a buffer provided by the BusyWithConnection function.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.077
EPSS Ranking 91.4%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2003-0849
-
cpe:2.3:a:gnu:cfengine:2.0.0
-
cpe:2.3:a:gnu:cfengine:2.0.1
-
cpe:2.3:a:gnu:cfengine:2.0.2
-
cpe:2.3:a:gnu:cfengine:2.0.3
-
cpe:2.3:a:gnu:cfengine:2.0.4
-
cpe:2.3:a:gnu:cfengine:2.0.5
-
cpe:2.3:a:gnu:cfengine:2.0.6
-
cpe:2.3:a:gnu:cfengine:2.0.7
-
cpe:2.3:a:gnu:cfengine:2.1.0