|
|
| |
|
| |
bidwatcher: format string vulnerability
| Package(s): | bidwatcher |
CVE #(s): | CAN-2005-0158
|
| Created: | February 18, 2005 |
Updated: | March 3, 2005 |
| Description: |
Ulf Härnhammar from the Debian Security Audit Project discovered a
format string vulnerability in bidwatcher, a tool for watching and
bidding on eBay auctions. This problem can be triggered remotely by a
web server of eBay, or someone pretending to be eBay, sending certain
data back. As of version 1.3.17 the program uses cURL and is not
vulnerable anymore. |
| Alerts: |
|
( Log in to post comments)
|
|
|