Perdition Vanessa_Logger Format String Vulnerability
BID:3740
Info
Perdition Vanessa_Logger Format String Vulnerability
| Bugtraq ID: | 3740 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 25 2001 12:00AM |
| Updated: | Dec 25 2001 12:00AM |
| Credit: | This vulnerability was published to the VulnWatch mailing list in a GOBBLES advisory on December 25th, 2001. |
| Vulnerable: |
Vanessa vanessa_logger 0.0.1 |
| Not Vulnerable: |
Vanessa vanessa_logger 0.0.2 |
Discussion
Perdition Vanessa_Logger Format String Vulnerability
A remotely exploitable format string problem exists in the vanessa_logger library. It is possible for an attacker to exploit this issue to overwrite almost arbitrary locations in memory, potentially resulting in the execution of attacker-supplied code.
Other software that uses the vulnerable vanessa_logger library will also be prone to this issue.
A remotely exploitable format string problem exists in the vanessa_logger library. It is possible for an attacker to exploit this issue to overwrite almost arbitrary locations in memory, potentially resulting in the execution of attacker-supplied code.
Other software that uses the vulnerable vanessa_logger library will also be prone to this issue.
Exploit / POC
Perdition Vanessa_Logger Format String Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Perdition Vanessa_Logger Format String Vulnerability
Solution:
FreeBSD has made a patch available for Perdition v0.0.1
The vendor has released an upgrade which addresses this issue.
Fixes:
Vanessa vanessa_logger 0.0.1
Solution:
FreeBSD has made a patch available for Perdition v0.0.1
The vendor has released an upgrade which addresses this issue.
Fixes:
Vanessa vanessa_logger 0.0.1
-
FreeBSD patch-libvanessa_logger::vanessa_logger.c
http://www.freebsd.org/cgi/cvsweb.cgi/ports/devel/libvanessa_logger/fi les/patch-libvanessa_logger%3a%3avanessa_logger.c -
Vanessa vanessa_logger-0.0.2.tar.gz
ftp://ftp.vergenet.net/pub/vanessa/vanessa_logger/0.0.2/vanessa_logger -0.0.2.tar.gz
References
Perdition Vanessa_Logger Format String Vulnerability
References:
References:
- [VulnWatch] GOBBLES #17: perdition/vanessa_logger format string vuln (VulnWatch)
- Perdition Homepage (Perdition)
- VAnessa Libraries Homepage (VAnessa)