PT-2006-6939 · Elog · Elog
Arun Kethipelly
+1
·
Published
2006-12-28
·
Updated
2011-03-08
·
CVE-2006-6318
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
elog versions 2.6.2 and earlier
Description
The issue allows remote authenticated users to cause a denial of service, resulting in a daemon crash. This occurs when attempting to access a logbook whose name begins with "global", leading to a NULL pointer dereference in the
show elog list function.Recommendations
For elog versions 2.6.2 and earlier, consider restricting access to logbooks whose names begin with "global" to prevent the daemon crash until a fix is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Elog