Bug 17911 - mars_nwe format string errors
mars_nwe format string errors
Status: CLOSED RAWHIDE
Product: Red Hat Linux
Classification: Retired
Component: mars-nwe (Show other bugs)
6.2
All Linux
medium Severity medium
: ---
: ---
Assigned To: Bill Nottingham
:
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2000-09-29 18:02 EDT by Jarno Huuskonen
Modified: 2014-03-16 22:16 EDT (History)
1 user (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2000-09-29 18:02:32 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:


Attachments (Terms of Use)

  None (edit)
Description Jarno Huuskonen 2000-09-29 18:02:31 EDT
Hi,

I found some (possible) format string errors in mars_nwe:
tools.c:L192
syslog(LOG_DEBUG, buf);

tools.c:L252
syslog(prio, buf);

I don't know if these are exploitable, but they look quite risky.
(They require that mars_nwe has syslogging enabled in /etc/nw??.conf)

-Jarno
Comment 1 Bill Nottingham 2001-01-19 15:57:34 EST
Fixed in mars-nwe-0.99.pl20-1.

Note You need to log in before you can comment on or make changes to this bug.