people.freebsd.org
http://people.freebsd.org/~niels/issues/nbsmtp-20050726.txt CVE-2005-2409
nbSMTP 0.99 - 'util.c' Client-Side Command Execution
Record summary
CVE-2005-2409 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Format string vulnerability in util.c in nbsmtp 0.99 and earlier, while running in debug mode, allows remote attackers to execute arbitrary code via format string specifiers that are not properly handled in a syslog call.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBnbSMTP 0.99 - 'util.c' Client-Side Command ExecutionExploitDB exploitby CoKiNot analyzed1 file
References
716279Third-party advisory
http://secunia.com/advisories/16279 16324Third-party advisory
http://secunia.com/advisories/16324 14441vdb entry
http://www.securityfocus.com/bid/14441 vuxml.orgConfirmation
http://www.vuxml.org/freebsd/debbb39c-fdb3-11d9-a30d-00b0d09acbfc.html nbsmtp-format-string(21674)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/21674 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2005-2409