Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

zkfingerd say() Format String Vulnerability

zkfingerd is prone to a format string vulnerability. The affected function does not perform sufficient checks when displaying user-supplied input. It is possible to corrupt memory by passing format strings through the vulnerable function. This may potentially be exploited to overwrite arbitrary locations in memory with attacker-specified values.

Successful exploitation of this issue may allow the attacker to execute arbitrary instructions, possibly, with elevated privileges.







 

Privacy Statement
Copyright 2009, SecurityFocus