CVE-2009-0363
Severity CVSS v4.0:
Pending analysis
Type:
CWE-119
Buffer Errors
Publication date:
17/02/2009
Last modified:
09/04/2025
Description
Multiple buffer overflows in (a) BarnOwl before 1.0.5 and (b) owl 2.1.11 allow remote attackers to execute arbitrary code via vectors involving (1) a crafted zcrypt message, related to zcrypt.c; (2) a reply command on a message with a Zephyr Cc: list, related to zwrite.c; and unspecified other use of the products.
Impact
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:barnowl:barnowl:*:*:*:*:*:*:*:* | 1.0.4.1 (including) | |
| cpe:2.3:a:barnowl:barnowl:1.0.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:barnowl:barnowl:1.0.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:barnowl:barnowl:1.0.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:barnowl:barnowl:1.0.2.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:barnowl:barnowl:1.0.3:*:*:*:*:*:*:* | ||
| cpe:2.3:a:barnowl:barnowl:1.0.4:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ktools:owl:2.1.11:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://barnowl.mit.edu/browser/ChangeLog
- http://barnowl.mit.edu/wiki/barnowl-1.0.5-announce
- http://bugs.debian.org/515118
- http://www.mail-archive.com/debian-testing-security-announce%40lists.debian.org/msg00173.html
- https://bugs.launchpad.net/ubuntu/+source/owl/+bug/329165
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48824
- http://barnowl.mit.edu/browser/ChangeLog
- http://barnowl.mit.edu/wiki/barnowl-1.0.5-announce
- http://bugs.debian.org/515118
- http://www.mail-archive.com/debian-testing-security-announce%40lists.debian.org/msg00173.html
- https://bugs.launchpad.net/ubuntu/+source/owl/+bug/329165
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48824



