Stefan Frings SMS Server Tools Local Format String Vulnerability
BID:16188
Info
Stefan Frings SMS Server Tools Local Format String Vulnerability
| Bugtraq ID: | 16188 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-0083 |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 09 2006 12:00AM |
| Updated: | Jul 05 2006 06:49PM |
| Credit: | Ulf Harnhammar from the Debian Security Audit project discovered this vulnerability. |
| Vulnerable: |
SMS Server Tools SMS Server Tools 1.14.8 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 Debian Linux 3.0 sparc Debian Linux 3.0 s/390 Debian Linux 3.0 ppc Debian Linux 3.0 mipsel Debian Linux 3.0 mips Debian Linux 3.0 m68k Debian Linux 3.0 ia-64 Debian Linux 3.0 ia-32 Debian Linux 3.0 hppa Debian Linux 3.0 arm Debian Linux 3.0 alpha Debian Linux 3.0 |
| Not Vulnerable: | |
Discussion
Stefan Frings SMS Server Tools Local Format String Vulnerability
A local format-string vulnerability affects Stefan Frings SMS Server Tools.
The problem presents itself when the affected application tries to log messages using a formatted-print function. The application fails to properly sanitize user-supplied input before including it in the format-specifier argument of a formatted-print function.
An attacker may leverage this issue to execute arbitrary code with superuser privileges, ultimately facilitating privilege escalation.
Version 1.14.8 of SMS Server Tools is vulnerable to this issue; other versions may also be affected.
A local format-string vulnerability affects Stefan Frings SMS Server Tools.
The problem presents itself when the affected application tries to log messages using a formatted-print function. The application fails to properly sanitize user-supplied input before including it in the format-specifier argument of a formatted-print function.
An attacker may leverage this issue to execute arbitrary code with superuser privileges, ultimately facilitating privilege escalation.
Version 1.14.8 of SMS Server Tools is vulnerable to this issue; other versions may also be affected.
Exploit / POC
Stefan Frings SMS Server Tools Local Format String Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Solution / Fix
Stefan Frings SMS Server Tools Local Format String Vulnerability
Solution:
Please see the referenced advisories for more information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected].
SMS Server Tools SMS Server Tools 1.14.8
Solution:
Please see the referenced advisories for more information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected].
SMS Server Tools SMS Server Tools 1.14.8
-
Debian smstools_1.14.8-1sarge0_mipsel.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/ stable/updates main/ -
Debian smstools_1.14.8-1sarge0_alpha.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/ stable/updates main -
Debian smstools_1.14.8-1sarge0_alpha.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/ stable/updates main/ -
Debian smstools_1.14.8-1sarge0_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/ stable/updates main -
Debian smstools_1.14.8-1sarge0_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/ stable/updates main/ -
Debian smstools_1.14.8-1sarge0_arm.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/ stable/updates main -
Debian smstools_1.14.8-1sarge0_arm.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/ stable/updates main/ -
Debian smstools_1.14.8-1sarge0_hppa.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/ stable/updates main -
Debian smstools_1.14.8-1sarge0_hppa.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/ stable/updates main/ -
Debian smstools_1.14.8-1sarge0_i386.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/ stable/updates main -
Debian smstools_1.14.8-1sarge0_i386.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/ stable/updates main/ -
Debian smstools_1.14.8-1sarge0_ia64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/ stable/updates main -
Debian smstools_1.14.8-1sarge0_ia64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/ stable/updates main/ -
Debian smstools_1.14.8-1sarge0_m68k.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/ stable/updates main -
Debian smstools_1.14.8-1sarge0_m68k.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/ stable/updates main/ -
Debian smstools_1.14.8-1sarge0_mips.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/ stable/updates main -
Debian smstools_1.14.8-1sarge0_mips.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/ stable/updates main/ -
Debian smstools_1.14.8-1sarge0_mipsel.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/ stable/updates main -
Debian smstools_1.14.8-1sarge0_powerpc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/ stable/updates main -
Debian smstools_1.14.8-1sarge0_powerpc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/ stable/updates main/ -
Debian smstools_1.14.8-1sarge0_s390.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/ stable/updates main -
Debian smstools_1.14.8-1sarge0_s390.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/ stable/updates main/ -
Debian smstools_1.14.8-1sarge0_sparc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/ stable/updates main -
Debian smstools_1.14.8-1sarge0_sparc.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/ stable/updates main/ -
Debian smstools_1.5.0-2woody0_alpha.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/smstools/smstools_1.5.0 -2woody0_alpha.deb -
Debian smstools_1.5.0-2woody0_arm.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/smstools/smstools_1.5.0 -2woody0_arm.deb -
Debian smstools_1.5.0-2woody0_hppa.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/smstools/smstools_1.5.0 -2woody0_hppa.deb -
Debian smstools_1.5.0-2woody0_i386.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/smstools/smstools_1.5.0 -2woody0_i386.deb -
Debian smstools_1.5.0-2woody0_ia64.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/smstools/smstools_1.5.0 -2woody0_ia64.deb -
Debian smstools_1.5.0-2woody0_m68k.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/smstools/smstools_1.5.0 -2woody0_m68k.deb -
Debian smstools_1.5.0-2woody0_mips.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/smstools/smstools_1.5.0 -2woody0_mips.deb -
Debian smstools_1.5.0-2woody0_mipsel.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/smstools/smstools_1.5.0 -2woody0_mipsel.deb -
Debian smstools_1.5.0-2woody0_powerpc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/smstools/smstools_1.5.0 -2woody0_powerpc.deb -
Debian smstools_1.5.0-2woody0_s390.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/smstools/smstools_1.5.0 -2woody0_s390.deb -
Debian smstools_1.5.0-2woody0_sparc.deb
Debian GNU/Linux 3.0 alias woody
http://security.debian.org/pool/updates/main/s/smstools/smstools_1.5.0 -2woody0_sparc.deb
References
Stefan Frings SMS Server Tools Local Format String Vulnerability
References:
References:
- SMS Server Tools Home Page (Stefan Frings)