Off-by-one buffer overflow in the context_action function in context.c of Logsurfer 1.41 through 1.5a allows remote attackers to cause a denial of service (crash) via a malformed log entry.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/5898 | vdb entry patch |
ftp://ftp.cert.dfn.de/pub/tools/audit/logsurfer/logsurfer.README.asc | |
http://www.iss.net/security_center/static/10287.php | vdb entry patch |
http://online.securityfocus.com/archive/1/294131 | mailing list |