Vulnerability Description
The HTTP client and server in giFT-FastTrack 0.8.6 and earlier allows remote attackers to cause a denial of service (crash), possibly via an empty search query, which triggers a NULL dereference.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gift-Fasttrack | Gift-Fasttrack | 0.8.0 |
| Gentoo | Linux | 1.4 |
References
- http://developer.berlios.de/bugs/?func=detailbug&bug_id=1573&group_id=809
- http://gift-fasttrack.berlios.de/
- http://secunia.com/advisories/11941/
- http://www.gentoo.org/security/en/glsa/glsa-200406-19.xmlVendor Advisory
- http://www.securityfocus.com/bid/10604PatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16508
- http://developer.berlios.de/bugs/?func=detailbug&bug_id=1573&group_id=809
- http://gift-fasttrack.berlios.de/
- http://secunia.com/advisories/11941/
- http://www.gentoo.org/security/en/glsa/glsa-200406-19.xmlVendor Advisory
- http://www.securityfocus.com/bid/10604PatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16508
FAQ
What is CVE-2004-0604?
CVE-2004-0604 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The HTTP client and server in giFT-FastTrack 0.8.6 and earlier allows remote attackers to cause a denial of service (crash), possibly via an empty search query, which triggers a NULL dereference.
How severe is CVE-2004-0604?
CVE-2004-0604 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2004-0604?
Check the references section above for vendor advisories and patch information. Affected products include: Gift-Fasttrack Gift-Fasttrack, Gentoo Linux.