Vulnerability Details CVE-2004-1289
Multiple buffer overflows in (1) the getline function in pcalutil.c and (2) the get_holiday function in readfile.c for pcal 4.7.1 allow remote attackers to execute arbitrary code via a crafted calendar file.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.193
EPSS Ranking 95.1%
CVSS Severity
CVSS v2 Score 10.0
Products affected by CVE-2004-1289
-
cpe:2.3:a:pcal:pcal:4.1.0
-
cpe:2.3:a:pcal:pcal:4.3.0
-
cpe:2.3:a:pcal:pcal:4.5.0
-
cpe:2.3:a:pcal:pcal:4.6.0
-
cpe:2.3:a:pcal:pcal:4.7.0
-
cpe:2.3:a:pcal:pcal:4.7.1