DECFingerD Format String Vulnerability
BID:5105
Info
DECFingerD Format String Vulnerability
| Bugtraq ID: | 5105 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 25 2002 12:00AM |
| Updated: | Jun 25 2002 12:00AM |
| Credit: | Discovery of this issue is credited to isox <[email protected]>. |
| Vulnerable: |
decfingerd decfingerd 0.7 |
| Not Vulnerable: | |
Discussion
DECFingerD Format String Vulnerability
The Deception Finger Daemon (decfingerd) is prone to a format string vulnerability. This may be exploited by remote attackers to potentially execute arbitrary instructions with the privileges of the decfingerd process (normally root).
This problem is the result of unsafe use of the syslog() to log externally supplied data.
The Deception Finger Daemon (decfingerd) is prone to a format string vulnerability. This may be exploited by remote attackers to potentially execute arbitrary instructions with the privileges of the decfingerd process (normally root).
This problem is the result of unsafe use of the syslog() to log externally supplied data.
Exploit / POC
DECFingerD Format String Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
DECFingerD Format String Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
DECFingerD Format String Vulnerability
References:
References: