1 results (0.003 seconds)

CVSS: 9.3EPSS: 59%CPEs: 8EXPL: 0

Multiple buffer overflows in Cscope before 15.7a allow remote attackers to execute arbitrary code via long strings in input such as (1) source-code tokens and (2) pathnames, related to integer overflows in some cases. NOTE: this issue exists because of an incomplete fix for CVE-2004-2541. Múltiples desbordamientos de búfer en Cscope anterior a versión 15.7a, permiten a los atacantes remotos ejecutar código arbitrario por medio de cadenas largas en entradas como (1) tokens de código fuente y (2) nombres de ruta, relacionados con desbordamiento de enteros en algunos casos. NOTA: este problema se presenta debido a una corrección incompleta del CVE-2004-2541. • http://lists.apple.com/archives/security-announce/2009/May/msg00002.html http://secunia.com/advisories/34978 http://secunia.com/advisories/35074 http://secunia.com/advisories/35213 http://secunia.com/advisories/35214 http://secunia.com/advisories/35462 http://security.gentoo.org/glsa/glsa-200905-02.xml http://sourceforge.net/forum/forum.php?forum_id=947983 http://sourceforge.net/mailarchive/forum.php?thread_name=E1LsGx3-00015K-TN%40ddv4jf1.ch3.sourceforge.com&forum_name=cscope-cvs http:&# • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •