fwknop before 2.0.3 allow remote authenticated users to cause a denial of service (server crash) or possibly execute arbitrary code.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
http://www.openwall.com/lists/oss-security/2012/09/19/2 | mailing list exploit third party advisory |
http://www.openwall.com/lists/oss-security/2012/09/20/4 | mailing list exploit third party advisory |
http://www.cipherdyne.org/blog/2012/09/software-release-fwknop-2.0.3.html | release notes vendor advisory |