Back to search
CVE-2006-5790
Published: Nov 7, 2006
Modified: Aug 7, 2024
PUBLISHED
Description
Multiple format string vulnerabilities in elogd.c in ELOG 2.6.2 and earlier allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) an entry with an attachment whose name contains format string specifiers (el_submit function), and possibly other vectors in the (2) receive_config, (3) show_rss_feed, (4) show_elog_list, (5) show_logbook_node, and (6) server_loop functions.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
23580
third-party-advisory
x_refsource_SECUNIA
DSA-1242
vendor-advisory
x_refsource_DEBIAN
20876
vdb-entry
x_refsource_BID
elog-elsubmit-format-string(29987)
vdb-entry
x_refsource_XF
22638
third-party-advisory
x_refsource_SECUNIA
ADV-2006-4315
vdb-entry
x_refsource_VUPEN
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=392016
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now