Logsurfer 'prepare_exec()' Double Free Local Denial of Service Vulnerability
BID:50171
Info
Logsurfer 'prepare_exec()' Double Free Local Denial of Service Vulnerability
| Bugtraq ID: | 50171 |
| Class: | Unknown |
| CVE: |
CVE-2011-3626 |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 17 2011 12:00AM |
| Updated: | Jan 20 2012 09:10PM |
| Credit: | Gregor Kopf of Recurity Labs |
| Vulnerable: |
Logsurfer Logsurfer 1.7 Logsurfer Logsurfer 1.5b Logsurfer Logsurfer 1.5 Gentoo Linux |
| Not Vulnerable: | |
Discussion
Logsurfer 'prepare_exec()' Double Free Local Denial of Service Vulnerability
Logsurfer is prone to a local denial-of-service vulnerability due to a double-free condition.
A local attacker can exploit this issue to crash the affected application, denying service to legitimate users. Due to the nature of this issue, arbitrary code-execution may be possible; however this has not been confirmed.
Logsurfer is prone to a local denial-of-service vulnerability due to a double-free condition.
A local attacker can exploit this issue to crash the affected application, denying service to legitimate users. Due to the nature of this issue, arbitrary code-execution may be possible; however this has not been confirmed.
Exploit / POC
Logsurfer 'prepare_exec()' Double Free Local Denial of Service Vulnerability
An attacker can exploit this issue via readily available tools.
An attacker can exploit this issue via readily available tools.
Solution / Fix
Logsurfer 'prepare_exec()' Double Free Local Denial of Service Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Logsurfer 'prepare_exec()' Double Free Local Denial of Service Vulnerability
References:
References:
- CVE request: double-free vulnerability in logsurfer (Timo Warns)
- LogSurfer Homepage (LogSurfer)