CVE-2009-0363

EUVD-2009-0367
Multiple buffer overflows in (a) BarnOwl before 1.0.5 and (b) owl 2.1.11 allow remote attackers to execute arbitrary code via vectors involving (1) a crafted zcrypt message, related to zcrypt.c; (2) a reply command on a message with a Zephyr Cc: list, related to zwrite.c; and unspecified other use of the products.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 88%
Affected Products (NVD)
VendorProductVersion
barnowlbarnowl
𝑥
≤ 1.0.4.1
barnowlbarnowl
1.0.0
barnowlbarnowl
1.0.1
barnowlbarnowl
1.0.2
barnowlbarnowl
1.0.2.1
barnowlbarnowl
1.0.3
barnowlbarnowl
1.0.4
ktoolsowl
2.1.11
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
barnowl
bookworm
1.10-2
fixed
bullseye
1.10-2
fixed
etch
no-dsa
lenny
no-dsa
sid
1.10-2
fixed
trixie
1.10-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
barnowl
dapper
dne
gutsy
dne
hardy
dne
intrepid
ignored
jaunty
not-affected
karmic
not-affected
lucid
not-affected
maverick
not-affected
natty
not-affected
oneiric
not-affected
owl
dapper
ignored
gutsy
ignored
hardy
ignored
intrepid
ignored
jaunty
not-affected
karmic
not-affected
lucid
not-affected
maverick
not-affected
natty
not-affected
oneiric
not-affected