Michael Krax log2mail Log File Writing Format String Vulnerability
BID:10460
Info
Michael Krax log2mail Log File Writing Format String Vulnerability
| Bugtraq ID: | 10460 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 03 2004 12:00AM |
| Updated: | Jun 03 2004 12:00AM |
| Credit: | Disclosure of this issue is credited to [email protected]. |
| Vulnerable: |
log2mail log2mail 0.2.5 .2 log2mail log2mail 0.2.5 .1 log2mail log2mail 0.2.5 .0 log2mail log2mail 0.2.2 .2 |
| Not Vulnerable: | |
Discussion
Michael Krax log2mail Log File Writing Format String Vulnerability
Michael Krax log2mail is reported prone to a log file writing format string vulnerability. This issue is due to a failure of the application to properly implement a formatted string function.
This vulnerability will ultimately allow for execution of arbitrary code on a system running the affected software. This would occur in the security context of the user invoking the vulnerable application; typically the 'log2mail' user with group 'adm'.
Michael Krax log2mail is reported prone to a log file writing format string vulnerability. This issue is due to a failure of the application to properly implement a formatted string function.
This vulnerability will ultimately allow for execution of arbitrary code on a system running the affected software. This would occur in the security context of the user invoking the vulnerable application; typically the 'log2mail' user with group 'adm'.
Exploit / POC
Michael Krax log2mail Log File Writing Format String Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Michael Krax log2mail Log File Writing Format String Vulnerability
Solution:
Debian has issued advisory DSA 513-1 dealing with this issue. Please see the referenced advisory for more information.
log2mail log2mail 0.2.5 .2
Solution:
Debian has issued advisory DSA 513-1 dealing with this issue. Please see the referenced advisory for more information.
log2mail log2mail 0.2.5 .2
-
Debian log2mail_0.2.5.2_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/l/log2mail/log2mail_0.2.5 .2_alpha.deb -
Debian log2mail_0.2.5.2_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/l/log2mail/log2mail_0.2.5 .2_arm.deb -
Debian log2mail_0.2.5.2_hppa.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/l/log2mail/log2mail_0.2.5 .2_hppa.deb -
Debian log2mail_0.2.5.2_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/l/log2mail/log2mail_0.2.5 .2_i386.deb -
Debian log2mail_0.2.5.2_ia64.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/l/log2mail/log2mail_0.2.5 .2_ia64.deb -
Debian log2mail_0.2.5.2_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/l/log2mail/log2mail_0.2.5 .2_m68k.deb -
Debian log2mail_0.2.5.2_mips.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/l/log2mail/log2mail_0.2.5 .2_mips.deb -
Debian log2mail_0.2.5.2_mipsel.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/l/log2mail/log2mail_0.2.5 .2_mipsel.deb -
Debian log2mail_0.2.5.2_powerpc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/l/log2mail/log2mail_0.2.5 .2_powerpc.deb -
Debian log2mail_0.2.5.2_s390.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/l/log2mail/log2mail_0.2.5 .2_s390.deb -
Debian log2mail_0.2.5.2_sparc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/l/log2mail/log2mail_0.2.5 .2_sparc.deb
References
Michael Krax log2mail Log File Writing Format String Vulnerability
References:
References:
- Project Home Page (log2mail)