PT-2023-10267 · Ayttm · Ayttm

Kapil A

·

Published

2023-03-05

·

Updated

2024-05-17

·

CVE-2015-10088

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ayttm versions up to 0.5.0.89
Description A critical vulnerability was found in ayttm, affecting the function http connect in the library libproxy/proxy.c. The manipulation leads to a format string issue, which can be initiated remotely. The complexity of an attack is rather high, and the exploitability is difficult.
Recommendations To fix this issue, it is recommended to apply a patch named 40e04680018614a7d2b68566b261b061a0597046 for versions up to 0.5.0.89. As a temporary workaround, consider disabling the http connect function in the libproxy/proxy.c library until a patch is available.

Fix

Use of Externally-Controlled Format String

Weakness Enumeration

Related Identifiers

CVE-2015-10088

Affected Products

Ayttm