Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

IKE-Scan Local Logging Format String Vulnerability

A vulnerability has been discovered in ike-scan. The problem is said to occur while making a call to syslog(). As a result, an attacker capable of influencing the data passed to syslog may be able to execute arbitrary code.

It should be noted that ike-scan is not suid by default.







 

Privacy Statement
Copyright 2009, SecurityFocus