Format string vulnerability in the logging functionality in BitDefender AntiVirus 7.2 through 9 allows remote attackers to cause a denial of service and possibly execute arbitrary code via format string specifiers in file or directory name.
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.
Link | Tags |
---|---|
http://kb.bitdefender.com/KB261-en--Filename-Format-String-Vulnerability.html | broken link |
http://secunia.com/advisories/16991 | third party advisory permissions required |
http://securityreason.com/securityalert/45 | third party advisory |
http://www.securityfocus.com/bid/14968 | third party advisory vdb entry |
http://shadock.net/secubox/BitDefenderLoggingFunc.html | broken link |