PT-2008-2799 · Linux · Linux Kiss Server
Vashnukad
·
Publicado
2008-03-08
·
Atualizado
2024-02-14
·
CVE-2008-1206
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Linux Kiss Server version 1.2
Description
The issue is related to a format string vulnerability in the log message function. This vulnerability can be exploited by remote attackers when the Linux Kiss Server is not running in background (daemon) mode. Attackers can cause a denial of service or potentially execute arbitrary code by including format string specifiers in an invalid command.
Recommendations
For Linux Kiss Server version 1.2, consider disabling the log message function in lks.c or restrict access to it until a patch is available. As a temporary workaround, enable background (daemon) mode to minimize the risk of exploitation.
Exploit
Correção
Use of Externally-Controlled Format String
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Linux Kiss Server