CVE-2005-2772

Publication date 2 September 2005

Last updated 17 July 2025


Ubuntu priority

Multiple stack-based buffer overflows in University of Minnesota gopher client 3.0.9 allow remote malicious servers to execute arbitrary code via (1) a long ”+VIEWS:” reply, which is not properly handled in the VIfromLine function, and (2) certain arguments when launching third party programs such as a web browser from a web link, which is not properly handled in the FIOgetargv function.

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
gopher 7.04 feisty
Fixed 3.0.11
6.10 edgy
Fixed 3.0.11
6.06 LTS dapper
Fixed 3.0.11