22 Oct 14:37
Exploit for OpenVMPS 1.3
From: <Hector.Ortiz@...>
Subject: Exploit for OpenVMPS 1.3
Newsgroups: gmane.network.freenac.devel
Date: 2006-10-22 12:37:29 GMT
Subject: Exploit for OpenVMPS 1.3
Newsgroups: gmane.network.freenac.devel
Date: 2006-10-22 12:37:29 GMT
Hi, I've found the next advisory: OpenVMPS is affected by a remote format-string vulnerability. The application fails to properly sanitize user-supplied input before using it as the format specifier in a system-log entry. Info and the exploit can be found at: http://www.securityfocus.com/bid/15072/info I've tested the exploit and seems to affect OpenVMPSd v1.3 (the one we use) running on Slackware 10.0, Debian 3.0 and Fedora Core 2. The exploit failed when I tested it in the development server, since we are running on a different distro. No patches have been released for this vulnerability. ------------------------------------------------------------------------- Using Tomcat but need to do more? Need to support web services, security? Get stuff done quickly with pre-integrated technology to make your job easier Download IBM WebSphere Application Server v.1.0.1 based on Apache Geronimo http://sel.as-us.falkag.net/sel?cmd=lnk&kid=120709&bid=263057&dat=121642
RSS Feed