Bugs item #531946, was opened at 2002-03-19 12:14
You can respond by visiting:
http://sourceforge.net/tracker/?func=detail&atid=103152&aid=531946&group_id=3152
Category: Architecture: Database
Group: aolserver3_4
Status: Open
Resolution: None
Priority: 5
Submitted By: Kriston Rehberg (kriston)
Assigned to: Kriston Rehberg (kriston)
Summary: DB Proxy Daemon Format String Vulnerabil
Initial Comment:
The Laboratory intexxia found a format string
vulnerability in
the AOL Server external database driver proxy daemon
API that could lead
to a privilege escalation.
________________________________________________________________________
DETAILS
=======
AOL Server provides an API to develop
external database driver
proxy daemons. Those daemons are linked to a library
(libnspd.a).
The Laboratory intexxia found a format string and a
buffer overflow
vulnerability in the 'Ns_PdLog' function of the
library. Successful
exploitation of the bug could allow an attacker to
execute code and get
access on the system.
As a result, all the External Driver Proxy Daemons
using the 'Ns_PdLog'
function with the 'Error' or 'Notice' parameter
are potentially
vulnerable.
----------------------------------------------------------------------
You can respond by visiting:
http://sourceforge.net/tracker/?func=detail&atid=103152&aid=531946&group_id=3152