PT-2002-2678 · Pen · Pen

Published

2002-12-31

·

Updated

2008-09-05

·

CVE-2002-1957

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Pen versions 0.9.1 through 0.9.2
Description The issue is related to a buffer overflow in the netlog function, located in the pen.c file. This allows remote attackers to execute arbitrary commands by sending malformed log messages.
Recommendations For versions 0.9.1 and 0.9.2, update to a version that fixes the buffer overflow issue in the netlog function.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-1957

Affected Products

Pen