PT-2001-2081 · Gnome · Libgtop

Publicado

2001-11-27

·

Atualizado

2016-10-18

·

CVE-2001-0927

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions libgtop versions 1.0.12 and earlier
Description The issue is related to a format string vulnerability in the permitted function of GNOME libgtop daemon. This vulnerability allows remote attackers to execute arbitrary code by passing arguments that contain format specifiers into the (1) syslog message and (2) syslog io message functions.
Recommendations For libgtop versions 1.0.12 and earlier, consider restricting access to the vulnerable functions until a patch is available. As a temporary workaround, avoid using the syslog message and syslog io message functions with untrusted input. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2001-0927

Produtos afetados

Libgtop