Buffer overflow in the addchar function in common/parseconf.c in upsd in Network UPS Tools (NUT) before 2.6.4 allows remote attackers to execute arbitrary code or cause a denial of service (electric-power outage) via a long string containing non-printable characters.
CVSS Details
- CVSS 3.1 Base Score: 7.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade nut | Jul 30, 2024 | Jun 1, 2012 |
| Freebsd | — | Upgrade nut | Dec 10, 2025 | May 30, 2012 |
| Gentoo Linux | — | Upgrade sys-power/nut. | Oct 30, 2017 | Jun 1, 2012 |
| Suse | — | Upgrade nut-develUpgrade libupsclient1Upgrade libnutscan2Upgrade nut-classicUpgrade nut-doc-imagesUpgrade nut-drivers-netUpgrade libupsclient7Upgrade libnutscan4Upgrade libnutconf0Upgrade libupsclient6Upgrade nutUpgrade libnutclient2Upgrade libnutclientstub1Upgrade nut-cgiUpgrade nut-doc-asciidocUpgrade nut-doc-html | Dec 12, 2013 | Jun 28, 2013 |
| Ubuntu | — | Upgrade nut-serverUpgrade nut | Nov 8, 2024 | Jun 1, 2012 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub