LWN.net Logo

cfingerd: code execution

Package(s):cfingerd CVE #(s):CVE-2013-1049
Created:March 1, 2013 Updated:March 6, 2013
Description:

From the Debian advisory:

Malcolm Scott discovered a remote-exploitable buffer overflow in the rfc1413 (ident) client of cfingerd, a configurable finger daemon. This vulnerability was introduced in a previously applied patch to the cfingerd package in 1.4.3-3.

Alerts:
Debian DSA-2635-1 2013-03-01

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds