VendorsInfodromcfingerdall versions
Vulnerabilities

Infodrom cfingerd

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2001-0609
Format string vulnerability in Infodrom cfingerd 1.4.3 and earlier allows a remote attacker to gain additional privileges via a malformed ident reply that is passed to the syslog function.
Published 2001-07-27 · Modified
10.02 PoCEPSS 0.182
CVE-2001-0735
Buffer overflow in cfingerd 1.4.3 and earlier with the ALLOW_LINE_PARSING option enabled allows local users to execute arbitrary code via a long line in the .nofinger file.
Published 2001-10-12 · Modified
7.23 PoCEPSS 0.016
CVE-1999-0708
Buffer overflow in cfingerd allows local users to gain root privileges via a long GECOS field.
Published 2000-01-18 · Modified
7.21 PoCEPSS 0.008
CVE-1999-0813
Cfingerd with ALLOW_EXECUTION enabled does not properly drop privileges when it executes a program on behalf of the user, allowing local users to gain root privileges.
Published 2000-04-18 · Modified
7.2EPSS 0.005
CVE-1999-0259
cfingerd lists all users on a system via search.**@target.
Published 2000-01-18 · Modified
5.0EPSS 0.014