Multiple Vendor Cfengine Format...

- AV AC AU C I A
发布: 2000-10-01
修订: 2025-04-13

Cfengine is a language-based system for testing and configuring unix-like systems attached to a TCP/IP network. cfd, the cfengine daemon component which serves as a remote-configuration client to cfengine, contains several improperly-designed calls to syslog(). As a result, trusted hosts (or any user, if access controls are not employed) may create and transmit a malicious message to the network daemon containing user-supplied format specifiers. At the very least, it is easy for a user to crash the service. By sending certain format specifiers, it is also possible for malicious users to write to portions of the program's stack and alter the flow of execution. If successful, an attcker can have arbitrary code execute with the privileges of the daemon (root). The following is excerpted verbatim from the original bugtraq posting by Pekka Savola <Pekka.Savola@netcore.fi>: "VERSIONS AND PLATFORMS AFFECTED: -------------------------------- Every recent version except 1.6.0a11 released on...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息