Multiple format string vulnerabilities in Empire Server before 4.3.1 allow attackers to cause a denial of service (crash) via the (1) load, (2) spy and (3) bomb functions.
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.
Link | Tags |
---|---|
http://sourceforge.net/project/shownotes.php?release_id=410001&group_id=24031 | patch |
https://exchange.xforce.ibmcloud.com/vulnerabilities/25863 | vdb entry |
http://www.vupen.com/english/advisories/2006/1380 | vdb entry vendor advisory |
http://www.securityfocus.com/bid/17585 | vdb entry |
http://www.osvdb.org/24700 | vdb entry |
http://secunia.com/advisories/19674 | patch vendor advisory third party advisory |