PT-2008-2799 · Linux · Linux Kiss Server
Vashnukad
·
Published
2008-03-08
·
Updated
2024-02-14
·
CVE-2008-1206
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Linux Kiss Server version 1.2
Description
The issue is related to a format string vulnerability in the log message function. This vulnerability can be exploited by remote attackers when the Linux Kiss Server is not running in background (daemon) mode. Attackers can cause a denial of service or potentially execute arbitrary code by including format string specifiers in an invalid command.
Recommendations
For Linux Kiss Server version 1.2, consider disabling the log message function in lks.c or restrict access to it until a patch is available. As a temporary workaround, enable background (daemon) mode to minimize the risk of exploitation.
Exploit
Fix
Use of Externally-Controlled Format String
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linux Kiss Server