oss-sec mailing list archives

Re: CVE request: httrack buffer overflow


From: "Steven M. Christey" <coley () linus mitre org>
Date: Mon, 4 Aug 2008 12:37:28 -0400 (EDT)


On Mon, 4 Aug 2008, Thijs Kinkhorst wrote:

On Monday 4 August 2008 12:21, Tomas Hoger wrote:
CVE-2008-3429 ?

Buffer overflow in URI processing in HTTrack and WinHTTrack before
3.42-3 allows remote attackers to cause a denial of service (crash) and
possibly execute arbitrary code via a long URL.

http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-3429

Thanks! I somehow missed that one...

It's in NVD but not yet on the public CVE site, due to various process
oddities.  98% of the time, NVD will have the CVEs before the CVE web site
does.

- Steve


Current thread: