Format string vulnerability in the LogMsg function in sercd before 2.3.1 and sredird 2.2.1 and earlier allows remote attackers to execute arbitrary code via format string specifiers passed from the HandleCPCCommand function.
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/11031 | vdb entry patch |
http://securitytracker.com/id?1011038 | vdb entry |
http://secunia.com/advisories/12351 | third party advisory vendor advisory |
http://www.osvdb.org/8375 | vdb entry patch |
http://www.securityfocus.com/bid/11002 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/17056 | vdb entry |
http://cvs.lysator.liu.se/viewcvs/viewcvs.cgi/sercd/sercd.c?root=sercd | |
http://www.osvdb.org/9104 | vdb entry |