Format string vulnerability in cfd daemon in GNU CFEngine before 1.6.0a11 allows attackers to execute arbitrary commands via format characters in the CAUTH command.
Info
Summary
Format string vulnerability in cfd daemon in GNU CFEngine before 1.6.0a11 allows attackers to execute arbitrary commands via format characters in the CAUTH command.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-013.txt.asc
- http://archives.neohapsis.com/archives/bugtraq/2000-10/0004.html
- http://www.linux-mandrake.com/en/security/MDKSA-2000-061.php3?dis=7.1 Patch
- http://www.securityfocus.com/bid/1757 Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5630
- ftp://ftp.NetBSD.ORG/pub/NetBSD/misc/security/advisories/NetBSD-SA2000-013.txt.asc
- http://archives.neohapsis.com/archives/bugtraq/2000-10/0004.html
- http://www.linux-mandrake.com/en/security/MDKSA-2000-061.php3?dis=7.1 Patch
- http://www.securityfocus.com/bid/1757 Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/5630
Timeline
- nvd_ingest NVD