CyberSec.Space Logo
返回 CVE 浏览器

CVE-2004-0989

CRITICAL
10.0
CVSS Severity Score
EPSS Score0.1720%
EPSS Percentile42.28th
Published2005年3月1日
Last Modified2026年4月16日

Vulnerability Description

Multiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and possibly other versions, may allow remote attackers to execute arbitrary code via (1) a long FTP URL that is not properly handled by the xmlNanoFTPScanURL function, (2) a long proxy URL containing FTP data that is not properly handled by the xmlNanoFTPScanProxy function, and other overflows related to manipulation of DNS length values, including (3) xmlNanoFTPConnect, (4) xmlNanoHTTPConnectHost, and (5) xmlNanoHTTPConnectHost.

Affected Platforms (CPE)

📦
Xmlsoft

Libxml

= 1.8.17
📦
Xmlsoft

Libxml2

= 2.5.11
📦
Xmlsoft

Libxml2

= 2.6.6
📦
Xmlsoft

Libxml2

= 2.6.7
📦
Xmlsoft

Libxml2

= 2.6.8
📦
Xmlsoft

Libxml2

= 2.6.9
📦
Xmlsoft

Libxml2

= 2.6.11
📦
Xmlsoft

Libxml2

= 2.6.12
📦
Xmlsoft

Libxml2

= 2.6.13
📦
Xmlsoft

Libxml2

= 2.6.14
📦
Xmlstarlet

Command Line Xml Toolkit

= 0.9.1
💻
Redhat

Fedora Core

= core_2.0
💻
Trustix

Secure Linux

= 2.0
💻
Trustix

Secure Linux

= 2.1
💻
Ubuntu

Ubuntu Linux

= 4.1
💻
Ubuntu

Ubuntu Linux

= 4.1

References & Advisories

相关漏洞威胁

CVE-2004-0989 Detail & Impact Analysis | CVSS 10.0 (CRITICAL) | Cyber-Sec.Space | Cyber-Sec.Space