CVE-2005-2772
gopher - buffer overflows
EPSS 33.1%
Description
Multiple stack-based buffer overflows in University of Minnesota gopher client 3.0.9 allow remote malicious servers to execute arbitrary code via (1) a long "+VIEWS:" reply, which is not properly handled in the VIfromLine function, and (2) certain arguments when launching third party programs such as a web browser from a web link, which is not properly handled in the FIOgetargv function.
How to fix CVE-2005-2772
To remediate CVE-2005-2772, upgrade the affected package to a fixed version below.
- Debian/gopher—upgrade to 3.0.11 or later
- —upgrade to 3.0.3woody4 or later
Is CVE-2005-2772 being exploited?
Moderate — EPSS is 33.1%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (2)
- from 0, < 3.0.11
- from 0, < 3.0.3woody4