CVE Database
/

CVE-2004-1702

Back to search

CVE-2004-1702

Published: Feb 21, 2005

Modified: Aug 8, 2024

PUBLISHED

Description

The AuthenticationDialogue function in cfservd for Cfengine 2.0.0 to 2.1.7p1 does not properly check the return value of the ReceiveTransaction function, which leads to a failed malloc call and triggers to a null dereference, which allows remote attackers to cause a denial of service (crash).

VendorProductVersions

n/a

n/a

affected
n/a

References

12251
third-party-advisory
x_refsource_SECUNIA
cfengine-cfservd-dos(16937)
vdb-entry
x_refsource_XF
10900
vdb-entry
x_refsource_BID
GLSA-200408-08
vendor-advisory
x_refsource_GENTOO

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now