|
MMFTPD SysLog Format String Vulnerability
mmftpd is a freely available, open source FTP server for Linux operating systems. Due to improper use of the syslog call, a problem exists which could make the execution of arbitrary code possible. A syslog call in the program which logs user-supplied information could be exploited to print to specified places in memory, including potentially overwriting the return address of a function and executing arbitrary code. |
|
|
Privacy Statement |