ELOG Web Logbook is reported prone to multiple vulnerabilities. The following individual issues are reported: ELOG Web Logbook is reported prone to two remote heap-based buffer overflow vulnerabilities. It is reported that the overflows may be leveraged remotely to have arbitrary code executed in the context of the affected daemon. A directory traversal vulnerability is also reported to affect ELOG Web Logbook; again, the details of this issue are not specified. It is conjectured that this issue may be exploited by a remote attacker to disclose sensitive information. These vulnerabilities are reported to exist in ELOG versions up to and including version 2.5.6. Other versions might also be affected.
ELOG Web Logbook is reported prone to multiple vulnerabilities. The following individual issues are reported: ELOG Web Logbook is reported prone to two remote heap-based buffer overflow vulnerabilities. It is reported that the overflows may be leveraged remotely to have arbitrary code executed in the context of the affected daemon. A directory traversal vulnerability is also reported to affect ELOG Web Logbook; again, the details of this issue are not specified. It is conjectured that this issue may be exploited by a remote attacker to disclose sensitive information. These vulnerabilities are reported to exist in ELOG versions up to and including version 2.5.6. Other versions might also be affected.