Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

MMFTPD SysLog Format String Vulnerability

mmftpd is a freely available, open source FTP server for Linux operating systems.

Due to improper use of the syslog call, a problem exists which could make the execution of arbitrary code possible. A syslog call in the program which logs user-supplied information could be exploited to print to specified places in memory, including potentially overwriting the return address of a function and executing arbitrary code.







 

Privacy Statement
Copyright 2008, SecurityFocus