BitDefender Antivirus Logging Function Format String Vulnerability
BID:14968
Info
BitDefender Antivirus Logging Function Format String Vulnerability
| Bugtraq ID: | 14968 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Sep 28 2005 12:00AM |
| Updated: | Sep 28 2005 12:00AM |
| Credit: | fRoGGz of SecuBox Labs disclosed this issue. |
| Vulnerable: |
Softwin BitDefender 9.0 Softwin BitDefender 8.0 Softwin BitDefender 7.2 Softwin BitDefender 7.0 |
| Not Vulnerable: | |
Discussion
BitDefender Antivirus Logging Function Format String Vulnerability
BitDefender Antivirus is a proprietary antivirus product for multiple platforms.
A format string vulnerability affects the logging functionality of BitDefender Antivirus. This issue is due to a failure of the application to properly sanitize user-supplied input prior to passing it as the format specifier to a formatted printing function.
A remote attacker may leverage this issue to write to arbitrary process memory, facilitating code execution, and privilege escalation.
This issue was reported in BitDefender versions 7.2, 8, and 9 for Windows. Other versions and platforms may also be affected.
BitDefender Antivirus is a proprietary antivirus product for multiple platforms.
A format string vulnerability affects the logging functionality of BitDefender Antivirus. This issue is due to a failure of the application to properly sanitize user-supplied input prior to passing it as the format specifier to a formatted printing function.
A remote attacker may leverage this issue to write to arbitrary process memory, facilitating code execution, and privilege escalation.
This issue was reported in BitDefender versions 7.2, 8, and 9 for Windows. Other versions and platforms may also be affected.
Exploit / POC
BitDefender Antivirus Logging Function Format String Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
BitDefender Antivirus Logging Function Format String Vulnerability
Solution:
The vendor has released updates addressing this issue for all affected versions. Updates are available through the regular update function.
Solution:
The vendor has released updates addressing this issue for all affected versions. Updates are available through the regular update function.
References
BitDefender Antivirus Logging Function Format String Vulnerability
References:
References:
- BitDefender AntiVirus Scan Page (Softwin)
- Filename Format String Vulnerability (Softwin)