LWN.net Logo

bidwatcher: format string vulnerability

Package(s):bidwatcher CVE #(s):CAN-2005-0158
Created:February 18, 2005 Updated:March 3, 2005
Description: Ulf Härnhammar from the Debian Security Audit Project discovered a format string vulnerability in bidwatcher, a tool for watching and bidding on eBay auctions. This problem can be triggered remotely by a web server of eBay, or someone pretending to be eBay, sending certain data back. As of version 1.3.17 the program uses cURL and is not vulnerable anymore.
Alerts:
Gentoo 200503-06 2005-03-03
Debian DSA-687-1 2005-02-18

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds