Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Pam-PGSQL Username Logging Remote Format String Vulnerability

pam-pgsql has been reported prone to a remote format string vulnerability.

It has been reported that a remote attacker may supply malicious format string specifiers as a username, to a program that is requesting PAM authentication (HTTP, SSH, telnet, etc). The username will be later processed, during logging procedures in pam-pgsql. This issue may be levered to corrupt memory and execute arbitrary code.







 

Privacy Statement
Copyright 2008, SecurityFocus