PT-2023-10267 · Ayttm · Ayttm

Kapil A

·

Publicado

2023-03-05

·

Atualizado

2024-05-17

·

CVE-2015-10088

CVSS v3.1

8.1

Alta

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ayttm versions up to 0.5.0.89
Description A critical vulnerability was found in ayttm, affecting the function http connect in the library libproxy/proxy.c. The manipulation leads to a format string issue, which can be initiated remotely. The complexity of an attack is rather high, and the exploitability is difficult.
Recommendations To fix this issue, it is recommended to apply a patch named 40e04680018614a7d2b68566b261b061a0597046 for versions up to 0.5.0.89. As a temporary workaround, consider disabling the http connect function in the libproxy/proxy.c library until a patch is available.

Correção

Use of Externally-Controlled Format String

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-10088

Produtos afetados

Ayttm