IKE-Scan Local Logging Format String Vulnerability
BID:7897
Info
IKE-Scan Local Logging Format String Vulnerability
| Bugtraq ID: | 7897 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 13 2003 12:00AM |
| Updated: | Jun 13 2003 12:00AM |
| Credit: | The discovery of this vulnerability has been credited to "you dong-hun"(Xpl017Elz). |
| Vulnerable: |
NTA ike-scan 1.1 NTA ike-scan 1.0 |
| Not Vulnerable: |
NTA ike-scan 1.2 |
Discussion
IKE-Scan Local Logging Format String Vulnerability
A vulnerability has been discovered in ike-scan. The problem is said to occur while making a call to syslog(). As a result, an attacker capable of influencing the data passed to syslog may be able to execute arbitrary code.
It should be noted that ike-scan is not suid by default.
A vulnerability has been discovered in ike-scan. The problem is said to occur while making a call to syslog(). As a result, an attacker capable of influencing the data passed to syslog may be able to execute arbitrary code.
It should be noted that ike-scan is not suid by default.
Exploit / POC
IKE-Scan Local Logging Format String Vulnerability
An exploit has been developed by "you dong-hun" however it is not currently available to the public.
An exploit has been developed by "you dong-hun" however it is not currently available to the public.
Solution / Fix
IKE-Scan Local Logging Format String Vulnerability
Solution:
The vendor has addressed this issue in version 1.2 of the software. Users are advised to upgrade as soon as possible.
NTA ike-scan 1.0
NTA ike-scan 1.1
Solution:
The vendor has addressed this issue in version 1.2 of the software. Users are advised to upgrade as soon as possible.
NTA ike-scan 1.0
-
NTA ike-scan 1.2
http://www.nta-monitor.com/ike-scan/download.htm
NTA ike-scan 1.1
-
NTA ike-scan 1.2
http://www.nta-monitor.com/ike-scan/download.htm
References
IKE-Scan Local Logging Format String Vulnerability
References:
References: