VDB
CVE-2008-2468
CVE-2008-2468
PUBLISHED
CVSS 10 CRITICAL
Multiple buffer overflows in the QIP Server Service (aka qipsrvr.exe) in LANDesk Management Suite, Security Suite, and Server Manager 8.8 and earlier allow remote attackers to execute arbitrary code via a crafted heal request, related to the StringToMap and StringSize arguments.
EPSS 40.89% · 97.5th percentile
Risk Scores
CVSS 2.0
10
EPSS Score
40.89%
97.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| landesk | landesk_security_suite | 8.7, 0 |
| n/a | n/a | n/a |
| landesk | landesk_management_suite | 0, 8.7 |
| landesk | landesk_server_manager | 0, 8.7 |
Timeline
- CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Oct 30, 2023 EPSS Score
References
- VU#538011 third-party-advisory
- http://dvlabs.tippingpoint.com/advisory/TPTI-08-06 url
- ADV-2008-2588 vdb
- landesk-qip-bo(45154) vdb
- 4269 third-party-advisory
- http://community.landesk.com/support/docs/DOC-3276 url
- 31193 vdb
- 1020888 vdb
- 31888 third-party-advisory
- 20080915 TPTI-08-06: Landesk QIP Server Service Heal Packet Buffer Overflow mailing-list
- https://nvd.nist.gov/vuln/detail/CVE-2008-2468 advisory