Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2013-4147

Опубликовано: 09 авг. 2013
Источник: nvd
CVSS2: 7.5
EPSS Средний

Описание

Multiple format string vulnerabilities in Yet Another Radius Daemon (YARD RADIUS) 1.1.2 allow context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via format string specifiers in a request in the (1) log_msg function in log.c or (2) version or (3) build_version function in version.c.

Комментарий

Per: http://seclists.org/oss-sec/2013/q3/145

"Software name : YardRadius Version : 1.1.2-4"

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:yard_radius_project:yard_radius:1.1.2-4:*:*:*:*:*:*:*

EPSS

Процентиль: 93%
0.10566
Средний

7.5 High

CVSS2

Дефекты

CWE-134

Связанные уязвимости

ubuntu
больше 12 лет назад

Multiple format string vulnerabilities in Yet Another Radius Daemon (YARD RADIUS) 1.1.2 allow context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via format string specifiers in a request in the (1) log_msg function in log.c or (2) version or (3) build_version function in version.c.

debian
больше 12 лет назад

Multiple format string vulnerabilities in Yet Another Radius Daemon (Y ...

github
больше 3 лет назад

Multiple format string vulnerabilities in Yet Another Radius Daemon (YARD RADIUS) 1.1.2 allow context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via format string specifiers in a request in the (1) log_msg function in log.c or (2) version or (3) build_version function in version.c.

EPSS

Процентиль: 93%
0.10566
Средний

7.5 High

CVSS2

Дефекты

CWE-134