Format string vulnerability in srsexec in Sun Remote Services (SRS) Net Connect 3.2.3 and 3.2.4, as distributed in the SRS Proxy Core (SUNWsrspx) package, allows local users to gain privileges via format string specifiers in unspecified input that is logged through syslog.
References
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 00:34
Type | Values Removed | Values Added |
---|---|---|
References | () http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=610 - | |
References | () http://osvdb.org/40836 - | |
References | () http://secunia.com/advisories/27512 - Patch, Vendor Advisory | |
References | () http://sunsolve.sun.com/search/document.do?assetkey=1-26-103119-1 - Patch | |
References | () http://sunsolve.sun.com/search/document.do?assetkey=1-66-200581-1 - | |
References | () http://www.securityfocus.com/bid/26313 - Patch | |
References | () http://www.securitytracker.com/id?1018893 - | |
References | () http://www.vupen.com/english/advisories/2007/3711 - |
Information
Published : 2007-11-14 01:46
Updated : 2024-11-21 00:34
NVD link : CVE-2007-3880
Mitre link : CVE-2007-3880
CVE.ORG link : CVE-2007-3880
JSON object : View
Products Affected
sun
- sunos
- net_connect_software
CWE
CWE-134
Use of Externally-Controlled Format String