Title: Osiris Multiple Unspecified Remote Format String
Info
Disclosure
Jul 28, 2006
Discovery
Unknown
Dates
Exploit
Unknown
Solution
Unknown
Description
Osiris contains a flaw that may allow a remote attacker to cause a denial of service and possibly execute arbitrary code. The issue is due to multiple format string bugs, possibly related to the logging functionality. No further details have been provided.
Classification
Location:
Remote / Network Access,
Local / Remote,
Context Dependent
Attack Type:
Denial of Service,
Input Manipulation
Impact:
Loss of Integrity
Exploit:
Exploit Unknown
Disclosure:
OSVDB Verified,
Vendor Verified
Solution
Upgrade to version 4.0.6-1sarge1 for the Debian stable distribution (sarge). Upgrade to version 4.2.0-2 for the Debian unstable distribution (sid). Upgrade to version 4.2.1 of Osiris if using another distribution as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.