CVE-2004-0989
Summary
| CVE | CVE-2004-0989 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2005-03-01 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Multiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and possibly other versions, may allow remote attackers to execute arbitrary code via (1) a long FTP URL that is not properly handled by the xmlNanoFTPScanURL function, (2) a long proxy URL containing FTP data that is not properly handled by the xmlNanoFTPScanProxy function, and other overflows related to manipulation of DNS length values, including (3) xmlNanoFTPConnect, (4) xmlNanoHTTPConnectHost, and (5) xmlNanoHTTPConnectHost. |
Risk And Classification
Primary CVSS: v2.0 10 from [email protected]
AV:N/AC:L/Au:N/C:C/I:C/A:C
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Redhat | Fedora Core | core_2.0 | All | All | All |
| Operating System | Trustix | Secure Linux | 2.0 | All | All | All |
| Operating System | Trustix | Secure Linux | 2.1 | All | All | All |
| Operating System | Ubuntu | Ubuntu Linux | 4.1 | All | ia64 | All |
| Operating System | Ubuntu | Ubuntu Linux | 4.1 | All | ppc | All |
| Application | Xmlsoft | Libxml | 1.8.17 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.5.11 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.6.11 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.6.12 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.6.13 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.6.14 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.6.6 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.6.7 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.6.8 | All | All | All |
| Application | Xmlsoft | Libxml2 | 2.6.9 | All | All | All |
| Application | Xmlstarlet | Command Line Xml Toolkit | 0.9.1 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.osvdb.org/11179 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| Secunia - Advisories - Libxml2 Multiple Buffer Overflows | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| APPLE-SA-2005-01-25 Security Update 2005-001 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| Security Announcement | af854a3a-2127-422b-91ae-364da2661108 | www.novell.com | |
| www.osvdb.org/11324 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| Debian -- Security Information -- DSA-582-1 libxml | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Libxml2 Multiple Remote Stack Buffer Overflow Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit, Patch, Vendor Advisory |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| P-029: libxml and libxml2 Buffer Overflow | af854a3a-2127-422b-91ae-364da2661108 | www.ciac.org | |
| Home - Conectiva | af854a3a-2127-422b-91ae-364da2661108 | distro.conectiva.com.br | |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| www.osvdb.org/11180 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| 'libxml2 remote buffer overflows (not in xml parsing code though)' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Gentoo Linux Documentation -- libxml2: Remotely exploitable buffer overflow | af854a3a-2127-422b-91ae-364da2661108 | www.gentoo.org | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| usn/usn-89-1 - Ubuntu Linux | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| SecurityTracker.com Archives - Libxml2 URL Parsing and DNS Resolution Buffer Overflows May Let Remote Users Execute Arbitrary Code | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.