« Volver al listado

CVE-2008-0973

Estado: ModificadaAlta (7.5)—

Buffer overflow in Double-Take (aka HP StorageWorks Storage Mirroring) 4.5.0.1629, and other 4.5.0.x versions, allows remote attackers to have an unknown impact via a packet with a long string in the username field.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2008-0973",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": true,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2008-02-25T23:44:00.000",
  "references": [
    {
      "url": "http://aluigi.altervista.org/adv/doubletakedown-adv.txt",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://aluigi.org/poc/doubletakedown.zip",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/29075",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://securityreason.com/securityalert/3698",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/488632/100/0/threaded",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/27951",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2008/0666",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://aluigi.altervista.org/adv/doubletakedown-adv.txt",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://aluigi.org/poc/doubletakedown.zip",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/29075",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://securityreason.com/securityalert/3698",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/488632/100/0/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/27951",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2008/0666",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-119"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Buffer overflow in Double-Take (aka HP StorageWorks Storage Mirroring) 4.5.0.1629, and other 4.5.0.x versions, allows remote attackers to have an unknown impact via a packet with a long string in the username field."
    },
    {
      "lang": "es",
      "value": "Desbordamiento de Buffer en Double-Take (también conocido como HP StorageWorks Storage Mirroring) 4.5.0.1629 y otras  versiones 4.5.0.x, permite a atacantes remotos provocar un impacto desconocido a través de paquete de cadena larga en el campo username."
    }
  ],
  "lastModified": "2026-06-16T22:50:42.720",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:double-take_software:double-take:4.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F178F692-773F-4D8A-BA9C-78D448126649"
            },
            {
              "criteria": "cpe:2.3:a:double-take_software:double-take:5.0.0.2865:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "36F54C9F-55AA-4171-80E1-3B7F978B51AF"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "vendorComments": [
    {
      "comment": "This issue was fixed in version 5.1 which was released July  11, 2008",
      "lastModified": "2009-05-08T00:00:00",
      "organization": "Double-Take"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}