CVE-2005-2772

NameCVE-2005-2772
DescriptionMultiple stack-based buffer overflows in University of Minnesota gopher client 3.0.9 allow remote malicious servers to execute arbitrary code via (1) a long "+VIEWS:" reply, which is not properly handled in the VIfromLine function, and (2) certain arguments when launching third party programs such as a web browser from a web link, which is not properly handled in the FIOgetargv function.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-832-1
NVD severityhigh (attack range: remote)
Debian Bugs327722

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
gopher (PTS)wheezy, jessie3.0.13fixed
buster, sid, stretch3.0.16fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
gophersource(unstable)3.0.11high327722
gophersourcesarge3.0.7sarge2highDSA-832-1
gophersourcewoody3.0.3woody4highDSA-832-1

Search for package or bug name: Reporting problems