CVE-2003-0805

NameCVE-2003-0805
DescriptionMultiple buffer overflows in UMN gopher daemon (gopherd) 2.x and 3.x before 3.0.6 allows attackers to execute arbitrary code via (1) a long filename as a result of a LIST command, and (2) the GSisText function, which calculates the view-type.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-387
NVD severityhigh (attack range: remote)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
gopher (PTS)wheezy, jessie3.0.13fixed
buster, stretch, sid3.0.16fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
gophersource(unstable)3.0.6high
gophersourcewoody3.0.3woody1highDSA-387

Notes

gopherd was removed from the gopher package in version 3.0.6.

Search for package or bug name: Reporting problems