Elm Expires Header Remote Buffer Overflow Vulnerability

BID:14613

Info

Elm Expires Header Remote Buffer Overflow Vulnerability

Bugtraq ID: 14613
Class: Boundary Condition Error
CVE: CVE-2005-2665
Remote: Yes
Local: No
Published: Aug 20 2005 12:00AM
Updated: Jul 12 2009 05:06PM
Credit: Ulf Harnhammar <[email protected]> is credited with the discovery of this vulnerability.
Vulnerable: Winace Winace 2.6 05
Slackware Linux 10.2
Slackware Linux 10.1
Slackware Linux 10.0
Slackware Linux 9.1
Slackware Linux 9.0
Slackware Linux 8.1
Slackware Linux -current
Redhat Enterprise Linux AS 2.1 IA64
Redhat Enterprise Linux AS 2.1
Redhat Advanced Workstation for the Itanium Processor 2.1 IA64
Redhat Advanced Workstation for the Itanium Processor 2.1
Elm Development Group ELM 2.5.7
Elm Development Group ELM 2.5.6
Elm Development Group ELM 2.5.5
- Redhat Linux 7.1 alpha
Not Vulnerable: Elm Development Group ELM 2.5.8
Elm Development Group ELM ME+

Discussion

Elm Expires Header Remote Buffer Overflow Vulnerability

Elm is prone to a buffer overflow vulnerability which could allow an attacker to execute malicious code. This issue is due to a failure in the application to perform proper bounds checking on user-supplied data.

A successful attack can result in overflowing a finite sized buffer and may ultimately lead to arbitrary code execution in the context of the affected application.

Exploit / POC

Elm Expires Header Remote Buffer Overflow Vulnerability

c0ntex &lt;[email protected]&gt; has provided the following exploit:

Solution / Fix

Elm Expires Header Remote Buffer Overflow Vulnerability

Solution:
Reports indicate Elm versions ME+ and 2.5.8 are not vulnerable to this issue. This has not been confirmed by Symantec or the vendor.

Red Hat has released advisory RHSA-2005:755-07 to address this issue in affected operating systems. Please see the referenced advisory for more information.

Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.

Slackware Linux has released advisory SSA:2005-311-01 to address this issue in affected operating systems. Please see the referenced advisory for more information.


Elm Development Group ELM 2.5.5

Elm Development Group ELM 2.5.6

Elm Development Group ELM 2.5.7

References

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report