Patches item #533141, was opened at 2002-03-21 10:45
You can respond by visiting:
http://sourceforge.net/tracker/?func=detail&atid=303152&aid=533141&group_id=3152

Category: None
Group: None
Status: Open
Resolution: None
Priority: 9
Submitted By: Kriston Rehberg (kriston)
Assigned to: Kriston Rehberg (kriston)
Summary: DB Proxy Daemon Format String Vulnerabil

Initial Comment:
 The Laboratory intexxia found a format string
vulnerability in
the AOL Server external database driver proxy daemon
API that could lead
to a privilege escalation.


________________________________________________________________________



DETAILS
=======

AOL Server provides an API to develop
external database driver
proxy daemons. Those daemons are linked to a library
(libnspd.a).

The Laboratory intexxia found a format string and a
buffer overflow
vulnerability in the 'Ns_PdLog' function of the
library. Successful
exploitation of the bug could allow an attacker to
execute code and get
access on the system.

As a result, all the External Driver Proxy Daemons
using the 'Ns_PdLog'
function with the 'Error' or 'Notice' parameter
are potentially
vulnerable.

----------------------------------------------------------------------

You can respond by visiting:
http://sourceforge.net/tracker/?func=detail&atid=303152&aid=533141&group_id=3152

Reply via email to