Pam-PGSQL Username Logging Remote Format String Vulnerability
BID:8379
Info
Pam-PGSQL Username Logging Remote Format String Vulnerability
| Bugtraq ID: | 8379 |
| Class: | Input Validation Error |
| CVE: |
CVE-2003-0672 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 09 2003 12:00AM |
| Updated: | Jul 11 2009 10:56PM |
| Credit: | Discovery of this vulnerability has been credited to Florian Zumbiehl. |
| Vulnerable: |
Leon J Breedt pam-pgsql 0.5.2 Leon J Breedt pam-pgsql 0.5.1 |
| Not Vulnerable: | |
Discussion
Pam-PGSQL Username Logging Remote Format String Vulnerability
pam-pgsql has been reported prone to a remote format string vulnerability.
It has been reported that a remote attacker may supply malicious format string specifiers as a username, to a program that is requesting PAM authentication (HTTP, SSH, telnet, etc). The username will be later processed, during logging procedures in pam-pgsql. This issue may be levered to corrupt memory and execute arbitrary code.
pam-pgsql has been reported prone to a remote format string vulnerability.
It has been reported that a remote attacker may supply malicious format string specifiers as a username, to a program that is requesting PAM authentication (HTTP, SSH, telnet, etc). The username will be later processed, during logging procedures in pam-pgsql. This issue may be levered to corrupt memory and execute arbitrary code.
Exploit / POC
Pam-PGSQL Username Logging Remote Format String Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Pam-PGSQL Username Logging Remote Format String Vulnerability
Solution:
Debian has released a security advisory (DSA 370-1) to address this issue. Further information relating to obtaining and applying fixes can be found in the referenced advisory. Customers who are affected by this issue are advised to upgrade as soon as possible.
Solution:
Debian has released a security advisory (DSA 370-1) to address this issue. Further information relating to obtaining and applying fixes can be found in the referenced advisory. Customers who are affected by this issue are advised to upgrade as soon as possible.
References
Pam-PGSQL Username Logging Remote Format String Vulnerability
References:
References: