Hector.Ortiz | 22 Oct 14:37

Exploit for OpenVMPS 1.3

Hi, I've found the next advisory:

OpenVMPS is affected by a remote format-string vulnerability. The application fails to properly
sanitize user-supplied input before using it as the format specifier in a system-log entry.

Info and the exploit can be found at: http://www.securityfocus.com/bid/15072/info

I've tested the exploit and seems to affect OpenVMPSd v1.3 (the one we use) running on Slackware 10.0,
Debian 3.0 and Fedora Core 2. The exploit failed when I tested it in the development server, since we are
running on a different distro. 

No patches have been released for this vulnerability.

-------------------------------------------------------------------------
Using Tomcat but need to do more? Need to support web services, security?
Get stuff done quickly with pre-integrated technology to make your job easier
Download IBM WebSphere Application Server v.1.0.1 based on Apache Geronimo
http://sel.as-us.falkag.net/sel?cmd=lnk&kid=120709&bid=263057&dat=121642

Gmane