Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

ELOG Web Logbook Multiple Remote Unspecified Vulnerabilities

ELOG Web Logbook is reported prone to multiple vulnerabilities. The following individual issues are reported:

ELOG Web Logbook is reported prone to two remote heap-based buffer overflow vulnerabilities. It is reported that the overflows may be leveraged remotely to have arbitrary code executed in the context of the affected daemon.

A directory traversal vulnerability is also reported to affect ELOG Web Logbook; again, the details of this issue are not specified. It is conjectured that this issue may be exploited by a remote attacker to disclose sensitive information.

These vulnerabilities are reported to exist in ELOG versions up to and including version 2.5.6. Other versions might also be affected.







 

Privacy Statement
Copyright 2009, SecurityFocus