Vulnerability Details CVE-2004-2409
Buffer overflow in the sh_hash_compdata function for Samhain 1.8.9 through 2.0.1, when running in update mode ("-t update"), might allow attackers to execute arbitrary code.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 20.0%
CVSS Severity
CVSS v2 Score 7.2
Products affected by CVE-2004-2409
-
cpe:2.3:a:samhain_labs:samhain:1.8.10
-
cpe:2.3:a:samhain_labs:samhain:1.8.10a
-
cpe:2.3:a:samhain_labs:samhain:1.8.10b
-
cpe:2.3:a:samhain_labs:samhain:1.8.11
-
cpe:2.3:a:samhain_labs:samhain:1.8.12
-
cpe:2.3:a:samhain_labs:samhain:1.8.12a
-
cpe:2.3:a:samhain_labs:samhain:1.8.12b
-
cpe:2.3:a:samhain_labs:samhain:1.8.9
-
cpe:2.3:a:samhain_labs:samhain:2.0.0
-
cpe:2.3:a:samhain_labs:samhain:2.0.1