Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.14314
Category:Denial of Service
Title:CFEngine AuthenticationDialogue Vulnerability
Summary:CFEngine cfservd is prone to a remote heap-based buffer overrun; vulnerability.
Description:Summary:
CFEngine cfservd is prone to a remote heap-based buffer overrun
vulnerability.

Vulnerability Insight:
The vulnerability presents itself in the cfengine cfservd
AuthenticationDialogue() function. The issue exists due to a lack of sufficient boundary checks
performed on challenge data that is received from a client.

In addition, cfengine cfservd is prone to a remote denial of service vulnerability. The
vulnerability presents itself in the cfengine cfservd AuthenticationDialogue() function which is
responsible for processing SAUTH commands and also performing RSA based authentication. The
vulnerability presents itself because return values for several statements within the
AuthenticationDialogue() function are not checked.

Solution:
Update to version 2.1.8 or later.

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2004-1701
BugTraq ID: 10899
http://www.securityfocus.com/bid/10899
Bugtraq: 20040809 CORE-2004-0714: Cfengine RSA Authentication Heap Corruption (Google Search)
http://marc.info/?l=bugtraq&m=109208394910086&w=2
Bugtraq: 20050219 cfengine rsa heap remote exploit: part of PTjob project (Google Search)
http://marc.info/?l=bugtraq&m=110886670528775&w=2
http://security.gentoo.org/glsa/glsa-200408-08.xml
http://www.coresecurity.com/common/showdoc.php?idx=387&idxseccion=10
http://secunia.com/advisories/12251
XForce ISS Database: cfengine-cfservd-command-execution(16935)
https://exchange.xforce.ibmcloud.com/vulnerabilities/16935
Common Vulnerability Exposure (CVE) ID: CVE-2004-1702
BugTraq ID: 10900
http://www.securityfocus.com/bid/10900
XForce ISS Database: cfengine-cfservd-dos(16937)
https://exchange.xforce.ibmcloud.com/vulnerabilities/16937
CopyrightCopyright (C) 2005 David Maciejak

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.