SERCD, SREDIRD Syslog() Format String Vulnerability
BID:11031
Info
SERCD, SREDIRD Syslog() Format String Vulnerability
| Bugtraq ID: | 11031 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 01 2004 12:00AM |
| Updated: | Aug 01 2004 12:00AM |
| Credit: | Max Vozeler <[email protected]> disclosed this vulnerability to the vendors. |
| Vulnerable: |
Peter �?strand SERCD 2.3 .0 Denis Sbragion sredird 2.2.1 Denis Sbragion sredird 2.2 Denis Sbragion sredird 2.1 Denis Sbragion sredird 2.0 Denis Sbragion sredird 1.1.8 Denis Sbragion sredird 1.1.7 Denis Sbragion sredird 1.1.6 Denis Sbragion sredird 1.0 |
| Not Vulnerable: |
Peter �?strand SERCD 2.3.1 |
Discussion
SERCD, SREDIRD Syslog() Format String Vulnerability
It is reported that SERCD and SREDIRD both contain a format string vulnerability in their logging function. This issue is due to a failure of the applications to properly sanitize user-supplied input before using it as the format specifier in a formatted printing function.
Successful exploitation of this issue will allow an attacker to execute arbitrary code on the affected computer with the privileges of the affected package. These processes are commonly run as the superuser in order to access the serial port.
Versions of SERCD prior to 2.3.1, and all known versions of SREDIRD are reported susceptible to this vulnerability.
BID 11002 was split into this BID and BID 11033.
It is reported that SERCD and SREDIRD both contain a format string vulnerability in their logging function. This issue is due to a failure of the applications to properly sanitize user-supplied input before using it as the format specifier in a formatted printing function.
Successful exploitation of this issue will allow an attacker to execute arbitrary code on the affected computer with the privileges of the affected package. These processes are commonly run as the superuser in order to access the serial port.
Versions of SERCD prior to 2.3.1, and all known versions of SREDIRD are reported susceptible to this vulnerability.
BID 11002 was split into this BID and BID 11033.
Exploit / POC
SERCD, SREDIRD Syslog() Format String Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
SERCD, SREDIRD Syslog() Format String Vulnerability
Solution:
The vendor has released version 2.3.1 of the package to address this issue:
Peter �?strand SERCD 2.3 .0
Solution:
The vendor has released version 2.3.1 of the package to address this issue:
Peter �?strand SERCD 2.3 .0
-
Peter �?strand sercd-2.3.1.tar.gz
http://www.lysator.liu.se/~astrand/projects/sercd/sercd-2.3.1.tar.gz
References
SERCD, SREDIRD Syslog() Format String Vulnerability
References:
References:
- CVS Log for sercd.c revision 1.9 (Peter �?strand)
- SERCD Home Page (Peter �?strand)
- sredird Homepage (Denis Sbragion)
- sredird LogMsg() Format String Bug and HandleCPCCommand() Buffer Overflow May Le (SecurityTracker)