Format string vulnerability in the permitted function of GNOME libgtop_daemon in libgtop 1.0.12 and earlier allows remote attackers to execute arbitrary code via an argument that contains format specifiers that are passed into the (1) syslog_message and (2) syslog_io_message functions.
Link | Tags |
---|---|
http://marc.info/?l=bugtraq&m=100689302316077&w=2 | mailing list |
ftp://ftp.gnome.org/pub/GNOME/stable/sources/libgtop/libgtop-1.0.13.tar.gz | |
http://www.debian.org/security/2002/dsa-098 | patch vendor advisory |