William Deich Super SysLog Format String Vulnerability
BID:5367
Info
William Deich Super SysLog Format String Vulnerability
| Bugtraq ID: | 5367 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 31 2002 12:00AM |
| Updated: | Jul 31 2002 12:00AM |
| Credit: | Discovery credited to Gobbles <[email protected]>. |
| Vulnerable: |
William Deich super 3.18 William Deich super 3.17 William Deich super 3.16 William Deich super 3.12 |
| Not Vulnerable: |
William Deich super 3.19 |
Discussion
William Deich Super SysLog Format String Vulnerability
super is prone to a format string vulnerability. This problem is due to incorrect use of the syslog() function to log error messages. It is possible to corrupt memory by passing format strings through the vulnerable logging function. This may potentially be exploited to overwrite arbitrary locations in memory with attacker-specified values.
super is prone to a format string vulnerability. This problem is due to incorrect use of the syslog() function to log error messages. It is possible to corrupt memory by passing format strings through the vulnerable logging function. This may potentially be exploited to overwrite arbitrary locations in memory with attacker-specified values.
Exploit / POC
William Deich Super SysLog Format String Vulnerability
The following exploit has been provided by Gobbles <[email protected]>:
The following exploit has been provided by Gobbles <[email protected]>: