Lynx Syslog URI Format String Vulnerability
BID:6696
Info
Lynx Syslog URI Format String Vulnerability
| Bugtraq ID: | 6696 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 27 2001 12:00AM |
| Updated: | Dec 27 2001 12:00AM |
| Credit: | Discovery of this vulnerability is credited to "Larry W. Cashdollar" <[email protected]>. |
| Vulnerable: |
University of Kansas Lynx 2.8.5 dev.5 University of Kansas Lynx 2.8.5 dev.4 University of Kansas Lynx 2.8.5 dev.3 University of Kansas Lynx 2.8.5 dev.2 University of Kansas Lynx 2.8.4 rel.1 |
| Not Vulnerable: | |
Discussion
Lynx Syslog URI Format String Vulnerability
Lynx is reported to be prone to a format string vulnerability. This vulnerability is present if syslogging of URIs is enabled. The syslog() function that logs URIs omits format specifiers. If a malicious URI is logged which contains attacker-supplied format strings, it will be possible to trigger this condition in a vulnerable client.
This condition may be exploited via a link to a malicious URI in a webpage. When the malicious link is visited and logged by the client, it may cause arbitrary locations in memory to be corrupted with attacker-supplied values. This may result in arbitrary code execution in the security context of the client.
Lynx is reported to be prone to a format string vulnerability. This vulnerability is present if syslogging of URIs is enabled. The syslog() function that logs URIs omits format specifiers. If a malicious URI is logged which contains attacker-supplied format strings, it will be possible to trigger this condition in a vulnerable client.
This condition may be exploited via a link to a malicious URI in a webpage. When the malicious link is visited and logged by the client, it may cause arbitrary locations in memory to be corrupted with attacker-supplied values. This may result in arbitrary code execution in the security context of the client.
Exploit / POC
Lynx Syslog URI Format String Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Lynx Syslog URI Format String Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Lynx Syslog URI Format String Vulnerability
References:
References:
- Lynx format string vulnerability in URL logging. ("Larry W. Cashdollar"
)