The Platform Service Process (asampsp) in Fan-Out Driver Platform Services for Novell Identity Manager (IDM) 3.5.1 allows remote attackers to cause a denial of service (daemon crash) via unspecified network traffic that triggers a syslog message containing invalid format string specifiers, as demonstrated by a Nessus scan.
The product uses a function that accepts a format string as an argument, but the format string originates from an external source.
Link | Tags |
---|---|
http://securitytracker.com/id?1019144 | vdb entry patch |
http://www.securityfocus.com/bid/27028 | vdb entry |
http://osvdb.org/40104 | vdb entry |
http://support.novell.com/docs/Readmes/InfoDocument/patchbuilder/readme_5007560.html | patch |
http://secunia.com/advisories/28237 | third party advisory patch vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/39206 | vdb entry |
http://www.vupen.com/english/advisories/2007/4311 | vdb entry |