PT-2005-2710 · Ibsh · Iron Bars Shell
Publicado
2005-05-24
·
Atualizado
2008-09-05
·
CVE-2005-1738
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Iron Bars SHell (ibsh) versions prior to 0.3d
Description
The issue allows users to access files outside the home directory and possibly execute arbitrary code via certain inputs that are not properly handled in a syslog call. This is due to a format string vulnerability in the logPrintBadfile function in delbadfiles.c.
Recommendations
For versions prior to 0.3d, update to version 0.3d or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive files and directories to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Iron Bars Shell