PLP Tools plpnfsd Syslog Format String Vulnerability
BID:6715
Info
PLP Tools plpnfsd Syslog Format String Vulnerability
| Bugtraq ID: | 6715 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 29 2003 12:00AM |
| Updated: | Jan 29 2003 12:00AM |
| Credit: | Discovery of this vulnerability credited to Carl Livitt <[email protected]>. |
| Vulnerable: |
plptools plptools 0.11 plptools plptools 0.6 |
| Not Vulnerable: |
plptools plptools 0.12 |
Discussion
PLP Tools plpnfsd Syslog Format String Vulnerability
A vulnerability has been reported for plpnfsd that may result in an attacker obtaining elevated privileges on the vulnerable system.
Due to a programming error, it may be possible to exploit a format string vulnerability in plpnfsd. A logging function in plpnfsd contains insecure syslog() calls. This could result in the execution of attacker-supplied code.
In the event that this vulnerability is exploited, an attacker could cause arbitrary locations in memory to be corrupted with attacker-specified data and execute code with elevated privileges.
*** New information has been made available that suggests version 0.11 is vulnerable. It was previously believed that this issue was fixed in its release.
A vulnerability has been reported for plpnfsd that may result in an attacker obtaining elevated privileges on the vulnerable system.
Due to a programming error, it may be possible to exploit a format string vulnerability in plpnfsd. A logging function in plpnfsd contains insecure syslog() calls. This could result in the execution of attacker-supplied code.
In the event that this vulnerability is exploited, an attacker could cause arbitrary locations in memory to be corrupted with attacker-specified data and execute code with elevated privileges.
*** New information has been made available that suggests version 0.11 is vulnerable. It was previously believed that this issue was fixed in its release.
Exploit / POC
PLP Tools plpnfsd Syslog Format String Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
PLP Tools plpnfsd Syslog Format String Vulnerability
Solution:
PLP Tools 0.12 has been released which addresses this issue. Users are advised to upgrade as soon as possible.
plptools plptools 0.11
plptools plptools 0.6
Solution:
PLP Tools 0.12 has been released which addresses this issue. Users are advised to upgrade as soon as possible.
plptools plptools 0.11
-
plptools PLP Tools 0.12
http://sourceforge.net/projects/plptools/
plptools plptools 0.6
-
plptools PLP Tools 0.12
http://sourceforge.net/projects/plptools/
References
PLP Tools plpnfsd Syslog Format String Vulnerability
References:
References:
- PLP Tools Project Page (PLP Tools)
- Local root vuln in SuSE 8.0 plptools package (Carl Livitt
) - Re: Local root vuln in SuSE 8.0 plptools package (Roman Drahtmueller
)