CVE
- Id
- 3422
- CVE No.
- CVE-2001-0609
- Status
- Candidate
- Description
- Format string vulnerability in Infodrom cfingerd 1.4.3 and earlier allows a remote attacker to gain additional privileges via a malformed ident reply that is passed to the syslog function.
- Phase
- Modified (20040818)
- Votes
- ACCEPT(5) Baker, Bishop, Cole, Frech, Ziese | NOOP(2) Foat, Wall | REVIEWING(1) Christey
- Comments
- Christey> A very similar vulnerability - which perhaps should be | combined with this CAN according to CD:SF-LOC - is documented | in the following references: | | BUGTRAQ:20010621 cfingerd local vulnerability (possibly root) | URL:http://www.securityfocus.com/archive/1/Pine.LNX.4.33.0106212246190.31927-100000@ace | BUGTRAQ:20010712 Happy 3 month anniversary cfingerd remote bug! | URL:http://www.securityfocus.com/archive/1/Pine.LNX.4.33.0107120434070.10330-200000@clarity.local | BID:2915 | URL:http://www.securityfocus.com/bid/2915 | Christey> DELREF DEBIAN:DSA-048 [wrong CVE]