Sup Remote Syslog Format String Vulnerability
BID:10571
Info
Sup Remote Syslog Format String Vulnerability
| Bugtraq ID: | 10571 |
| Class: | Input Validation Error |
| CVE: |
CVE-2004-0451 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 19 2004 12:00AM |
| Updated: | Jul 12 2009 05:16AM |
| Credit: | Discovery is credited to [email protected]. |
| Vulnerable: |
sup sup 1.8 Debian Linux 3.0 sparc Debian Linux 3.0 s/390 Debian Linux 3.0 ppc Debian Linux 3.0 mipsel Debian Linux 3.0 mips Debian Linux 3.0 m68k Debian Linux 3.0 ia-64 Debian Linux 3.0 ia-32 Debian Linux 3.0 hppa Debian Linux 3.0 arm Debian Linux 3.0 alpha Debian Linux 3.0 |
| Not Vulnerable: | |
Discussion
Sup Remote Syslog Format String Vulnerability
sup is prone to a remotely exploitable format string vulnerability. This issue could be exploited to execute arbitrary code in the context of the supfilesrv process.
sup is prone to a remotely exploitable format string vulnerability. This issue could be exploited to execute arbitrary code in the context of the supfilesrv process.
Exploit / POC
Sup Remote Syslog Format String Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Sup Remote Syslog Format String Vulnerability
Solution:
Debian has released an advisory (DSA 521-1) and fixes to address this issue. See the referenced advisory for links to fixed packages.
Solution:
Debian has released an advisory (DSA 521-1) and fixes to address this issue. See the referenced advisory for links to fixed packages.
References
Sup Remote Syslog Format String Vulnerability
References:
References: