Weex Log_Flush() Function Remote Format String Vulnerability
BID:14999
Info
Weex Log_Flush() Function Remote Format String Vulnerability
| Bugtraq ID: | 14999 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-3150 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 02 2005 12:00AM |
| Updated: | Jul 12 2009 05:06PM |
| Credit: | Discovery is credited to Emanuel Haupt <[email protected]>. |
| Vulnerable: |
Weex Weex 2.6.1 .5 Weex Weex 2.6.1 Gentoo Linux |
| Not Vulnerable: | |
Discussion
Weex Log_Flush() Function Remote Format String Vulnerability
Weex is affected by a remote format string vulnerability.
The vulnerability presents itself in the 'log_flush()' function of the 'log.c' file and is exposed when the application attempts to write an error log entry containing format specifiers.
Weex versions 2.6.1 and 2.6.1.5 are reported to be vulnerable.
Weex is affected by a remote format string vulnerability.
The vulnerability presents itself in the 'log_flush()' function of the 'log.c' file and is exposed when the application attempts to write an error log entry containing format specifiers.
Weex versions 2.6.1 and 2.6.1.5 are reported to be vulnerable.
Exploit / POC
Weex Log_Flush() Function Remote Format String Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Weex Log_Flush() Function Remote Format String Vulnerability
Solution:
Gentoo Linux has released advisory GLSA 200510-09 to address this issue. Users of affected packages are urged to execute the following commands with superuser privileges:
emerge --sync
emerge --ask --oneshot --verbose ">=net-ftp/weex-2.6.1.5-r1"
Please see the referenced advisory for further information.
Debian has released advisory DSA 855-1 to address this issue. Please see the referenced advisory for more information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Gentoo Linux has released advisory GLSA 200510-09 to address this issue. Users of affected packages are urged to execute the following commands with superuser privileges:
emerge --sync
emerge --ask --oneshot --verbose ">=net-ftp/weex-2.6.1.5-r1"
Please see the referenced advisory for further information.
Debian has released advisory DSA 855-1 to address this issue. Please see the referenced advisory for more information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Weex Log_Flush() Function Remote Format String Vulnerability
References:
References:
- Home Page (Weex)
- Problem Report ports/86833 : maintainer-update: ftp/weex - fixing a remote forma (Emanuel Haupt
)