vendor:
slurp NNTP Client
by:
Unknown
7.5
CVSS
HIGH
Format String Vulnerability
134
CWE
Product Name: slurp NNTP Client
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: YES
Related CWE: CVE-2002-0697
CPE: a:slurp:slurp
Platforms Tested: Unix and Linux
Unknown
slurp NNTP Client syslog Function Format String Vulnerability
A format string vulnerability in the syslog function of slurp NNTP client allows a remote server to supply a custom format string that can write to an arbitrary address in memory.
Mitigation:
Upgrade to a version of slurp that has been patched for this vulnerability.