Vulnerability Description
Buffer overflow in utility.cpp in Turquoise SuperStat (turqstat) 2.2.4 and earlier might allow remote NNTP servers to execute arbitrary code via a date with a long month.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Softwolves Software | Turquoise Superstat | <= 2.2.3 |
References
- http://cvs.alioth.debian.org/cgi-bin/cvsweb.cgi/turqstat/utility.cpp.diff?cvsroo
- http://www.debian.org/security/2005/dsa-812PatchVendor Advisory
- http://www.securityfocus.com/bid/14852
- http://cvs.alioth.debian.org/cgi-bin/cvsweb.cgi/turqstat/utility.cpp.diff?cvsroo
- http://www.debian.org/security/2005/dsa-812PatchVendor Advisory
- http://www.securityfocus.com/bid/14852
FAQ
What is CVE-2005-2658?
CVE-2005-2658 is a vulnerability with a CVSS score of 7.5 (HIGH). Buffer overflow in utility.cpp in Turquoise SuperStat (turqstat) 2.2.4 and earlier might allow remote NNTP servers to execute arbitrary code via a date with a long month.
How severe is CVE-2005-2658?
CVE-2005-2658 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2005-2658?
Check the references section above for vendor advisories and patch information. Affected products include: Softwolves Software Turquoise Superstat.