FakeBO Syslog Format String Vulnerability
BID:7882
Info
FakeBO Syslog Format String Vulnerability
| Bugtraq ID: | 7882 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 12 2003 12:00AM |
| Updated: | Jun 12 2003 12:00AM |
| Credit: | Discovery of this vulnerability credited to KF [email protected]. |
| Vulnerable: |
FakeBO FakeBO 0.4.1 |
| Not Vulnerable: | |
Discussion
FakeBO Syslog Format String Vulnerability
A vulnerability has been reported for FakeBO that may result in an attacker obtaining elevated privileges on a target system.
Due to a programming error, it may be possible to exploit a format string vulnerability in the affected utility. Specifically, a logging function in FakeBO contains insecure syslog() calls. This could result in the execution of attacker-supplied code.
A vulnerability has been reported for FakeBO that may result in an attacker obtaining elevated privileges on a target system.
Due to a programming error, it may be possible to exploit a format string vulnerability in the affected utility. Specifically, a logging function in FakeBO contains insecure syslog() calls. This could result in the execution of attacker-supplied code.