Patches item #533141, was opened at 2002-03-21 10:45 You can respond by visiting: http://sourceforge.net/tracker/?func=detail&atid=303152&aid=533141&group_id=3152
Category: None Group: None Status: Open Resolution: None Priority: 9 Submitted By: Kriston Rehberg (kriston) Assigned to: Kriston Rehberg (kriston) Summary: DB Proxy Daemon Format String Vulnerabil Initial Comment: The Laboratory intexxia found a format string vulnerability in the AOL Server external database driver proxy daemon API that could lead to a privilege escalation. ________________________________________________________________________ DETAILS ======= AOL Server provides an API to develop external database driver proxy daemons. Those daemons are linked to a library (libnspd.a). The Laboratory intexxia found a format string and a buffer overflow vulnerability in the 'Ns_PdLog' function of the library. Successful exploitation of the bug could allow an attacker to execute code and get access on the system. As a result, all the External Driver Proxy Daemons using the 'Ns_PdLog' function with the 'Error' or 'Notice' parameter are potentially vulnerable. ---------------------------------------------------------------------- You can respond by visiting: http://sourceforge.net/tracker/?func=detail&atid=303152&aid=533141&group_id=3152
