Vulnerability Description
Multiple buffer overflows in LISTSERV 14.3 and 14.4, including LISTSERV Lite and HPO, with the web archive interface enabled, allow remote attackers to execute arbitrary code via unknown attack vectors related to the WA CGI. NOTE: technical details will be released after the grace period has ended on 20060603.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lsoft | Listserv | 14.3 |
References
- http://secunia.com/advisories/19106
- http://securitytracker.com/id?1015722PatchVendor Advisory
- http://www.kb.cert.org/vuls/id/841132US Government Resource
- http://www.lsoft.com/manuals/1.8e/relnotes/LISTSERV14.5-Release-Notes.html#wasecPatch
- http://www.ngssoftware.com/advisories/listserv_3.txt
- http://www.securityfocus.com/archive/1/426770/100/0/threaded
- http://www.securityfocus.com/bid/16951Patch
- http://www.vupen.com/english/advisories/2006/0824
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25168
- http://secunia.com/advisories/19106
- http://securitytracker.com/id?1015722PatchVendor Advisory
- http://www.kb.cert.org/vuls/id/841132US Government Resource
- http://www.lsoft.com/manuals/1.8e/relnotes/LISTSERV14.5-Release-Notes.html#wasecPatch
- http://www.ngssoftware.com/advisories/listserv_3.txt
- http://www.securityfocus.com/archive/1/426770/100/0/threaded
FAQ
What is CVE-2006-1044?
CVE-2006-1044 is a vulnerability with a CVSS score of 7.5 (HIGH). Multiple buffer overflows in LISTSERV 14.3 and 14.4, including LISTSERV Lite and HPO, with the web archive interface enabled, allow remote attackers to execute arbitrary code via unknown attack vector...
How severe is CVE-2006-1044?
CVE-2006-1044 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2006-1044?
Check the references section above for vendor advisories and patch information. Affected products include: Lsoft Listserv.