PT-2002-2678 · Pen · Pen
Published
2002-12-31
·
Updated
2008-09-05
·
CVE-2002-1957
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Pen versions 0.9.1 through 0.9.2
Description
The issue is related to a buffer overflow in the netlog function, located in the pen.c file. This allows remote attackers to execute arbitrary commands by sending malformed log messages.
Recommendations
For versions 0.9.1 and 0.9.2, update to a version that fixes the buffer overflow issue in the netlog function.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pen