apt-www-proxy Format String Vulnerability
BID:6340
Info
apt-www-proxy Format String Vulnerability
| Bugtraq ID: | 6340 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 09 2002 12:00AM |
| Updated: | Dec 09 2002 12:00AM |
| Credit: | Discovery of this vulnerability credited to "dong-h0un U" <[email protected]>. |
| Vulnerable: |
apt-www-proxy apt-www-proxy 0.1 |
| Not Vulnerable: | |
Discussion
apt-www-proxy Format String Vulnerability
apt-www-proxy is prone to a format string vulnerability. This problem is due to incorrect use of the syslog() function to log error messages. It is possible to corrupt memory by passing format strings through the vulnerable logging function. This may potentially be exploited to overwrite arbitrary locations in memory with attacker-specified values.
apt-www-proxy is prone to a format string vulnerability. This problem is due to incorrect use of the syslog() function to log error messages. It is possible to corrupt memory by passing format strings through the vulnerable logging function. This may potentially be exploited to overwrite arbitrary locations in memory with attacker-specified values.
Exploit / POC
apt-www-proxy Format String Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
apt-www-proxy Format String Vulnerability
Solution:
An unofficial patch has been provided by "dong-h0un U" <[email protected]>. Further details are available in the referenced message.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
An unofficial patch has been provided by "dong-h0un U" <[email protected]>. Further details are available in the referenced message.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
apt-www-proxy Format String Vulnerability
References:
References:
- Remote multiple vulnerability in apt-www-proxy. ("dong-h0un U"
)