Format string vulnerability in the logging functionality in BitDefender AntiVirus 7.2 through 9 allows remote attackers to cause a denial of service and possibly execute arbitrary code via format string specifiers in file or directory name.
                
            References
                    | Link | Resource | 
|---|---|
| http://kb.bitdefender.com/KB261-en--Filename-Format-String-Vulnerability.html | Broken Link | 
| http://secunia.com/advisories/16991 | Permissions Required | 
| http://securityreason.com/securityalert/45 | Third Party Advisory | 
| http://shadock.net/secubox/BitDefenderLoggingFunc.html | Broken Link | 
| http://www.securityfocus.com/bid/14968 | Third Party Advisory | 
| http://kb.bitdefender.com/KB261-en--Filename-Format-String-Vulnerability.html | Broken Link | 
| http://secunia.com/advisories/16991 | Permissions Required | 
| http://securityreason.com/securityalert/45 | Third Party Advisory | 
| http://shadock.net/secubox/BitDefenderLoggingFunc.html | Broken Link | 
| http://www.securityfocus.com/bid/14968 | Third Party Advisory | 
Configurations
                    Configuration 1 (hide)
            
            
  | 
    
History
                    21 Nov 2024, 00:01
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () http://kb.bitdefender.com/KB261-en--Filename-Format-String-Vulnerability.html - Broken Link | |
| References | () http://secunia.com/advisories/16991 - Permissions Required | |
| References | () http://securityreason.com/securityalert/45 - Third Party Advisory | |
| References | () http://shadock.net/secubox/BitDefenderLoggingFunc.html - Broken Link | |
| References | () http://www.securityfocus.com/bid/14968 - Third Party Advisory | 
Information
                Published : 2005-10-05 23:02
Updated : 2025-04-03 01:03
NVD link : CVE-2005-3154
Mitre link : CVE-2005-3154
CVE.ORG link : CVE-2005-3154
JSON object : View
Products Affected
                softwin
- bitdefender
 
CWE
                
                    
                        
                        CWE-134
                        
            Use of Externally-Controlled Format String
