PT-2005-5507 · Spey · Spey

Publicado

2005-12-31

·

Atualizado

2008-09-05

·

CVE-2005-4846

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Spey version 0.3.3
Description The issue allows attackers to cause a denial of service, potentially leading to a crash, and may also enable the execution of arbitrary code. This is achieved through the use of format string specifiers in a syslog call within the Logger.cc component.
Recommendations For Spey version 0.3.3, update to a version that fixes the format string vulnerability in Logger.cc to prevent potential denial of service and arbitrary code execution.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2005-4846

Produtos afetados

Spey