Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

PWC.CGI Syslog Format String Vulnerability

Solution:
Patch:

change
syslog(LOG_ERR, buffer);
to
syslog(LOG_ERR, "%s", buffer);








 

Privacy Statement
Copyright 2009, SecurityFocus