CVE-2003-0849 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 10.9% (pctl 96)
Patch early
A public exploit exists.
Description
Buffer overflow in net.c for cfengine 2.x before 2.0.8 allows remote attackers to execute arbitrary code via certain packets with modified length values, which is trusted by the ReceiveTransaction function when using a buffer provided by the BusyWithConnection function.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 10.9% — more likely to be exploited than 96% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2003-11-17 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| gnu | cfengine |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | GNU CFEngine 2.0.x - CFServD Transaction Packet Buffer Overrun (2) | 2003-11-04 |
| exploit-db | GNU CFEngine 2.-2.0.3 - Remote Stack Overflow | 2003-09-27 |
| exploit-db | GNU CFEngine 2.0.x - CFServD Transaction Packet Buffer Overrun (1) | 2003-09-25 |
References
→ the Explorer · watch your stack · NVD