CVE-2003-1228

Severity CVSS v4.0:
Pending analysis
Type:
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
31/12/2003
Last modified:
03/04/2025

Description

Buffer overflow in the prepare_reply function in request.c for Mathopd 1.2 through 1.5b13, and possibly earlier versions, allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via an HTTP request with a long path.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mathopd:mathopd:*:*:*:*:*:*:*:* 1.2 (including) 1.5 (excluding)
cpe:2.3:a:mathopd:mathopd:1.5:-:*:*:*:*:*:*
cpe:2.3:a:mathopd:mathopd:1.5:beta13:*:*:*:*:*:*