LWN.net Logo

log2mail: format string vulnerability

Package(s):log2mail CVE #(s):CAN-2004-0450
Created:June 3, 2004 Updated:June 9, 2004
Description: jaguar -at- felinemenace.org discovered a format string vulnerability in log2mail, whereby a user able to log a specially crafted message to a logfile monitored by log2mail (for example, via syslog) could cause arbitrary code to be executed with the privileges of the log2mail process. By default, this process runs as user 'log2mail', which is a member of group 'adm' (which has access to read system logfiles).
Alerts:
Debian DSA-513-1 2004-06-03

(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds