TANne Session Manager SysLog Format String Vulnerability
BID:6553
Info
TANne Session Manager SysLog Format String Vulnerability
| Bugtraq ID: | 6553 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 07 2003 12:00AM |
| Updated: | Jan 07 2003 12:00AM |
| Credit: | Vulnerability discovery credited to "dong-h0un yoU" <[email protected]>. |
| Vulnerable: |
TANne TANne 0.6.17 |
| Not Vulnerable: |
TANne TANne 0.7.1 |
Discussion
TANne Session Manager SysLog Format String Vulnerability
TANne is a freely available, open source session management package. It is available for Unix and Linux operating systems.
Due to programming error, it may be possible to exploit a format string vulnerability. A logging function in the TANne program contains insecure syslog() calls. This could result in the execution of attacker-supplied code.
TANne is a freely available, open source session management package. It is available for Unix and Linux operating systems.
Due to programming error, it may be possible to exploit a format string vulnerability. A logging function in the TANne program contains insecure syslog() calls. This could result in the execution of attacker-supplied code.