Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Salim Gasmi GLD Postfix Greylisting Daemon Format String Vulnerability

It is reported that GLD contains a format string vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied input data prior to using it in a formatted-printing function.

Remote attackers may exploit this vulnerability to cause arbitrary machine code to be executed in the context of the affected service. As the service is designed to be run as the superuser, remote attackers may gain superuser privileges on affected computers.

GLD version 1.4 is reportedly affected, but prior versions may also be affected.







 

Privacy Statement
Copyright 2008, SecurityFocus