zkfingerd SysLog Format String...

- AV AC AU C I A
发布: 2002-12-16
修订: 2025-04-13

zkfingerd is prone to a format string vulnerability. This problem is due to incorrect use of the 'syslog()' function to log error messages. It is possible to corrupt memory by passing format strings through the vulnerable logging function. This may potentially be exploited to overwrite arbitrary locations in memory with attacker-specified values. Successful exploitation of this issue may allow the attacker to execute arbitrary instructions, possibly, with elevated privileges.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息