S.u.S.E. ypbind-mt Format String...

- AV AC AU C I A
发布: 2000-10-18
修订: 2025-04-13

ypbind-mt is a rewrite of the NIS client software by Thorsten Kukuk for S.u.S.E. Linux systems. It has been reported that this version is vulnerable to a possibly remotely exploitable format string attack. The problem has to do with user input being passed as part of the format string argument for a *printf function. It is thus possible for a remote user to construct a format string that can cause the function to overwrite stack variables so that supplied shellcode can be executed. Successful exploitation of this vulnerability would yield root access for the attacker. The exact location of the bug in the ypbind-mt implementation is not known at this time.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息