~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to retired/CVE-2004-0989

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
PublicDate: 2005-03-01
2
 
Candidate: CVE-2004-0989
3
 
References:
4
 
 https://usn.ubuntu.com/usn/usn-89-1
5
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0989
6
 
Description:
7
 
 Multiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and
8
 
 possibly other versions, may allow remote attackers to execute arbitrary
9
 
 code via (1) a long FTP URL that is not properly handled by the
10
 
 xmlNanoFTPScanURL function, (2) a long proxy URL containing FTP data that
11
 
 is not properly handled by the xmlNanoFTPScanProxy function, and other
12
 
 overflows related to manipulation of DNS length values, including (3)
13
 
 xmlNanoFTPConnect, (4) xmlNanoHTTPConnectHost, and (5)
14
 
 xmlNanoHTTPConnectHost.
15
 
Ubuntu-Description:
16
 
Notes:
17
 
Bugs:
18
 
dapper_libxml2: released (2.6.24.dfsg-1ubuntu1)
19
 
edgy_libxml2: released (2.6.24.dfsg-1ubuntu1)
20
 
feisty_libxml2: released (2.6.24.dfsg-1ubuntu1)
21
 
devel_libxml2: released (2.6.24.dfsg-1ubuntu1)
22
 
dapper_libxml: released (1.8.17-12)
23
 
edgy_libxml: released (1.8.17-12)
24
 
feisty_libxml: released (1.8.17-12)
25
 
devel_libxml: released (1.8.17-12)
26
 
upstream_libxml: 
27
 
upstream_libxml2: