|
Family: Gain a shell remotely --> Category: mixed
PeerCast Format String Vulnerability Vulnerability Scan
Vulnerability Scan Summary Checks for format string vulnerability in PeerCast
Detailed Explanation for this Vulnerability Test
Synopsis :
The remote peer-to-peer application is affected by a format string
vulnerability.
Description :
The remote host is running PeerCast, a peer-to-peer software package
that lets users broadcast streaming media.
The version installed on the remote host suffers from a format string
vulnerability. A possible hacker can issue requests containing format
specifiers that will crash the server and potentially permit arbitrary
code execution subject to rights of the user under which the
affected application runs.
See also :
http://www.gulftech.org/?node=research&article_id=00077-05282005
http://archives.neohapsis.com/archives/bugtraq/2005-05/0335.html
http://www.peercast.org/forum/viewtopic.php?p=11596
Solution :
Upgrade to PeerCast 0.1212 or newer.
Threat Level:
Critical / CVSS Base Score : 10
(AV:R/AC:L/Au:NR/C:C/A:C/I:C/B:N)
Click HERE for more information and discussions on this network vulnerability scan.
|