OpenVMPS Logging Function Format String Vulnerability
BID:15072
Info
OpenVMPS Logging Function Format String Vulnerability
| Bugtraq ID: | 15072 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 11 2005 12:00AM |
| Updated: | Oct 24 2006 07:08PM |
| Credit: | mazahaquer is credited with the discovery of this vulnerability. |
| Vulnerable: |
OpenVMPS OpenVMPS 1.3 |
| Not Vulnerable: | |
Discussion
OpenVMPS Logging Function Format String Vulnerability
OpenVMPS is affected by a remote format-string vulnerability. The application fails to properly sanitize user-supplied input before using it as the format specifier in a system-log entry.
Remote attackers may exploit this issue to execute arbitrary machine code in the context of the affected service.
OpenVMPS is affected by a remote format-string vulnerability. The application fails to properly sanitize user-supplied input before using it as the format specifier in a system-log entry.
Remote attackers may exploit this issue to execute arbitrary machine code in the context of the affected service.
Exploit / POC
OpenVMPS Logging Function Format String Vulnerability
An exploit by barros and xgc is available.
An exploit by barros and xgc is available.
Solution / Fix
OpenVMPS Logging Function Format String Vulnerability
Solution:
The vendor has released fixes in its CVS repository. Please contact the vendor for information on obtaining and applying fixes. See the references for details.
Solution:
The vendor has released fixes in its CVS repository. Please contact the vendor for information on obtaining and applying fixes. See the references for details.
References
OpenVMPS Logging Function Format String Vulnerability
References:
References:
- OpenVMPS CVS (OpenVMPS)
- OpenVMPS Homepage (OpenVMPS)