PT-2002-1636 · Aol · Aolserver

Published

2002-06-11

·

Updated

2008-09-05

·

CVE-2002-0586

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions AOLServer versions 3.0 through 3.4.2
Description The issue concerns a format string vulnerability in the Ns PdLog function of the external database driver proxy daemon library. This vulnerability allows remote attackers to execute arbitrary code via the Error or Notice parameters.
Recommendations For AOLServer versions 3.0 through 3.4.2, consider restricting access to the Ns PdLog function until a patch is available. As a temporary workaround, avoid using the Error or Notice parameters in the affected library to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-0586

Affected Products

Aolserver