Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

GNU m4 Format String and Filename Quoting Vulnerabilities

GNU m4 is prone to format-string and filename-quoting vulnerabilities.

To exploit these issues, attackers would have to coerce unsuspecting users to use the affected utility on malicious filenames or file content.

Successful exploits of the format-string vulnerability may allow remote attackers to execute arbitrary machine code in the context of the affected utility, facilitating the remote compromise of affected computers. The filename-quoting issue may allow malicious users to read or modify unintended files, possibly aiding in further attacks.

Versions prior to GNU m4 1.4.11 are vulnerable.







 

Privacy Statement
Copyright 2009, SecurityFocus