OSVDB ID: 27645

Title: Osiris Multiple Unspecified Remote Format String

Info

Disclosure

Jul 28, 2006

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

Osiris contains a flaw that may allow a remote attacker to cause a denial of service and possibly execute arbitrary code. The issue is due to multiple format string bugs, possibly related to the logging functionality. No further details have been provided.

Classification

Location: Remote / Network Access, Local / Remote, Context Dependent
Attack Type: Denial of Service, Input Manipulation
Impact: Loss of Integrity
Exploit: Exploit Unknown
Disclosure: OSVDB Verified, Vendor Verified

Solution

Upgrade to version 4.0.6-1sarge1 for the Debian stable distribution (sarge). Upgrade to version 4.2.0-2 for the Debian unstable distribution (sid). Upgrade to version 4.2.1 of Osiris if using another distribution as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.

Products

Brian Wotring

Osiris

4.2.0

References

Credit

  • Ulf Härnhammar - Swedish IT Incident Centre
  • Max Vozeler - maxlinux.de -


Direct URL: http://osvdb.org/27645