20040507 Pound <=1.5 Remote Exploit (Format string bug)mailing list
http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0343.html CVE-2004-2026
APSIS Pound 1.5 - Remote Format String
Record summary
CVE-2004-2026 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Format string vulnerability in the logmsg function in svc.c for Pound 1.5 and earlier allows remote attackers to execute arbitrary code via format string specifiers in syslog messages.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBAPSIS Pound 1.5 - Remote Format StringExploitDB exploitby Nilanjan DeNot analyzed1 file
References
911528Third-party advisory
http://secunia.com/advisories/11528 GLSA-200405-08Vendor advisory
http://security.gentoo.org/glsa/glsa-200405-08.xml 1010034vdb entry
http://securitytracker.com/id?1010034 apsis.chConfirmation
http://www.apsis.ch/pound/pound_list/archive/2003/2003-12/1070234315000 5746vdb entry
http://www.osvdb.org/5746 10267vdb entry
http://www.securityfocus.com/bid/10267 pound-logmsg-format-string(16033)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/16033 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2004-2026