Security Advisory

CVE-2008-5279

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2008-11-29 02:00:00
Last updated 2024-08-07 10:49:11
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

The Local ZIM Server (zcs.exe) in Zilab Chat and Instant Messaging (ZIM) Server 2.1 and earlier allow remote attackers to execute arbitrary code via (1) heap-based buffer overflows involving multiple vectors including a long room name and a long source account, and (2) a stack-based buffer overflow with a long username in an information request. NOTE: some of these details are obtained from third party information.