PT-2012-1049 · Network Ups Tools+1 · Network Ups Tools+1

Sebastian Pohle

·

Publicado

2012-06-01

·

Atualizado

2024-06-15

·

CVE-2012-2944

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Network UPS Tools (NUT) versions prior to 2.6.4 nut versions prior to 2.6.3
Description The issue affects the confidentiality, integrity, and availability of protected information. It can be exploited remotely. A buffer overflow in the addchar function in common/parseconf.c in upsd allows remote attackers to execute arbitrary code or cause a denial of service.
Recommendations For versions prior to 2.6.4, update to version 2.6.4 or later to resolve the issue. For versions prior to 2.6.3, update to version 2.6.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the addchar function in common/parseconf.c to minimize the risk of exploitation.

Exploit

Correção

DoS

RCE

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-03319
BDU:2015-09674
CVE-2012-2944
DSA-2484-1
OPENSUSE-SU-2024:10009-1
SUSE-SU-2012_1077-1
SUSE-SU-2012_1077-2

Produtos afetados

Network Ups Tools
Suse