Format string vulnerability in ALPass 2.7 English and 3.02 Korean might allow user-assisted remote attackers to execute arbitrary code via format string specifiers in an fnm field in a folder-name record in an ALPASS DB (APW) file.
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.
Link | Tags |
---|---|
http://vuln.sg/alpass27-en.html | third party advisory exploit |
http://secunia.com/advisories/26616 | third party advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/36256 | vdb entry third party advisory |
http://www.securityfocus.com/bid/25435 | vdb entry third party advisory patch |