PublicDate: 2008-06-13 18:41:00 UTC Candidate: CVE-2008-2654 References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2654 Description: Off-by-one error in the read_client function in webhttpd.c in Motion 3.2.10 and earlier might allow remote attackers to execute arbitrary code via a long request to a Motion HTTP Control interface, which triggers a stack-based buffer overflow with some combinations of processor architecture and compiler. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_motion: upstream_motion: released (3.2.9-4) dapper_motion: ignored (reached end-of-life) feisty_motion: needed (reached end-of-life) gutsy_motion: needed (reached end-of-life) hardy_motion: ignored (reached end-of-life) intrepid_motion: not-affected (3.2.9-4) jaunty_motion: not-affected (3.2.9-4) karmic_motion: not-affected (3.2.9-4) lucid_motion: not-affected (3.2.9-4) maverick_motion: not-affected (3.2.9-4) natty_motion: not-affected (3.2.9-4) oneiric_motion: not-affected (3.2.9-4) devel_motion: not-affected (3.2.9-4)