Bug 17911 - mars_nwe format string errors
Summary: mars_nwe format string errors
Status: CLOSED RAWHIDE
Alias: None
Product: Red Hat Linux
Classification: Retired
Component: mars-nwe   
(Show other bugs)
Version: 6.2
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Bill Nottingham
QA Contact:
URL:
Whiteboard:
Keywords:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2000-09-29 22:02 UTC by Jarno Huuskonen
Modified: 2014-03-17 02:16 UTC (History)
1 user (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2000-09-29 22:02:32 UTC
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

Description Jarno Huuskonen 2000-09-29 22:02:31 UTC
Hi,

I found some (possible) format string errors in mars_nwe:
tools.c:L192
syslog(LOG_DEBUG, buf);

tools.c:L252
syslog(prio, buf);

I don't know if these are exploitable, but they look quite risky.
(They require that mars_nwe has syslogging enabled in /etc/nw??.conf)

-Jarno

Comment 1 Bill Nottingham 2001-01-19 20:57:34 UTC
Fixed in mars-nwe-0.99.pl20-1.


Note You need to log in before you can comment on or make changes to this bug.