PFinger Syslog Format String Vulnerability
BID:6403
Info
PFinger Syslog Format String Vulnerability
| Bugtraq ID: | 6403 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 16 2002 12:00AM |
| Updated: | Dec 16 2002 12:00AM |
| Credit: | Discovery of this vulnerability credited to "NGSSoftware Insight Security Research" <[email protected]>. |
| Vulnerable: |
PFinger PFinger 0.7.8 PFinger PFinger 0.7.7 PFinger PFinger 0.7.6 PFinger PFinger 0.7.5 |
| Not Vulnerable: | |
Discussion
PFinger Syslog Format String Vulnerability
PFinger is prone to a format string vulnerability. This problem is due to incorrect use of the 'syslog()' function to log error messages. It is possible to corrupt memory by passing format strings through the vulnerable logging function. This may potentially be exploited to overwrite arbitrary locations in memory with attacker-specified values. This issue can be exploited via a malformed response to a DNS lookup.
Successful exploitation of this issue may allow the attacker to execute arbitrary instructions with elevated privileges.
It has been suggested that this issue may not be exploitable with many available DNS resolvers, since the '%' character is not allowed in responses.
PFinger is prone to a format string vulnerability. This problem is due to incorrect use of the 'syslog()' function to log error messages. It is possible to corrupt memory by passing format strings through the vulnerable logging function. This may potentially be exploited to overwrite arbitrary locations in memory with attacker-specified values. This issue can be exploited via a malformed response to a DNS lookup.
Successful exploitation of this issue may allow the attacker to execute arbitrary instructions with elevated privileges.
It has been suggested that this issue may not be exploitable with many available DNS resolvers, since the '%' character is not allowed in responses.
Exploit / POC
PFinger Syslog Format String Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
PFinger Syslog Format String Vulnerability
Solution:
Fixes available:
PFinger PFinger 0.7.5
PFinger PFinger 0.7.6
PFinger PFinger 0.7.7
PFinger PFinger 0.7.8
Solution:
Fixes available:
PFinger PFinger 0.7.5
-
PFinger pfinger-0.7.9.tar.gz
ftp://ftp.xelia.ch/pub/unix/pfinger-0.7.9.tar.gz
PFinger PFinger 0.7.6
-
PFinger pfinger-0.7.9.tar.gz
ftp://ftp.xelia.ch/pub/unix/pfinger-0.7.9.tar.gz
PFinger PFinger 0.7.7
-
PFinger pfinger-0.7.9.tar.gz
ftp://ftp.xelia.ch/pub/unix/pfinger-0.7.9.tar.gz
PFinger PFinger 0.7.8
-
PFinger pfinger-0.7.9.tar.gz
ftp://ftp.xelia.ch/pub/unix/pfinger-0.7.9.tar.gz
References
PFinger Syslog Format String Vulnerability
References:
References:
- PFinger Homepage (PFinger)
- PFinger 0.7.8 format string vulnerability (#NISR16122002B) ("NGSSoftware Insight Security Research"
) - RE: PFinger 0.7.8 format string vulnerability (#NISR16122002B) (Stefan Esser
) - Re: PFinger 0.7.8 format string vulnerability (#NISR16122002B) (Andreas Tscharner
)