CVE-2005-2772

Publication date 2 September 2005

Last updated 17 July 2025


Ubuntu priority

Description

Multiple stack-based buffer overflows in University of Minnesota gopher client 3.0.9 allow remote malicious servers to execute arbitrary code via (1) a long "+VIEWS:" reply, which is not properly handled in the VIfromLine function, and (2) certain arguments when launching third party programs such as a web browser from a web link, which is not properly handled in the FIOgetargv function.

Status

Package Ubuntu Release Status
gopher 7.04 feisty
Fixed 3.0.11
6.10 edgy
Fixed 3.0.11
6.06 LTS dapper
Fixed 3.0.11


Access our resources on patching vulnerabilities