iMatix Xitami Multiple Format String Vulnerabilities
BID:28603
Info
iMatix Xitami Multiple Format String Vulnerabilities
| Bugtraq ID: | 28603 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-6520 CVE-2008-6519 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 03 2008 12:00AM |
| Updated: | Jul 06 2016 02:17PM |
| Credit: | bratax |
| Vulnerable: |
Imatix Xitami 2.5c2 |
| Not Vulnerable: | |
Discussion
iMatix Xitami Multiple Format String Vulnerabilities
Xitami is prone to multiple format-string vulnerabilities because the application fails to adequately sanitize user-supplied input before passing it as the format specifier to a formatted-printing function.
A remote attacker may potentially execute arbitrary code in the context of the affected application. Failed exploit attempts will likely result in a denial of service.
These issues affect Xitami 2.5c2; other versions may be affected as well.
Xitami is prone to multiple format-string vulnerabilities because the application fails to adequately sanitize user-supplied input before passing it as the format specifier to a formatted-printing function.
A remote attacker may potentially execute arbitrary code in the context of the affected application. Failed exploit attempts will likely result in a denial of service.
These issues affect Xitami 2.5c2; other versions may be affected as well.
Exploit / POC
iMatix Xitami Multiple Format String Vulnerabilities
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
A proof of concept is available:
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
A proof of concept is available:
Solution / Fix
iMatix Xitami Multiple Format String Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
iMatix Xitami Multiple Format String Vulnerabilities
References:
References: