Описание
Format string vulnerability in the ws_addarg function in webserver.c in mt-dappd in Firefly Media Server 0.2.4 and earlier allows remote attackers to execute arbitrary code via a stats method action to /xml-rpc with format string specifiers in the (1) username or (2) password portion of base64-encoded data on the "Authorization: Basic" HTTP header line.
Релиз | Статус | Примечание |
---|---|---|
dapper | DNE | |
devel | not-affected | 0.9~r1696-1.3build1 |
feisty | ignored | end of life, was needed |
gutsy | ignored | end of life, was needed |
hardy | not-affected | 0.9~r1696-1.1 |
intrepid | not-affected | 0.9~r1696-1.3build1 |
upstream | released | 0.9~r1696-1 |
Показывать по
Ссылки на источники
7.5 High
CVSS2
Связанные уязвимости
Format string vulnerability in the ws_addarg function in webserver.c in mt-dappd in Firefly Media Server 0.2.4 and earlier allows remote attackers to execute arbitrary code via a stats method action to /xml-rpc with format string specifiers in the (1) username or (2) password portion of base64-encoded data on the "Authorization: Basic" HTTP header line.
Format string vulnerability in the ws_addarg function in webserver.c i ...
Format string vulnerability in the ws_addarg function in webserver.c in mt-dappd in Firefly Media Server 0.2.4 and earlier allows remote attackers to execute arbitrary code via a stats method action to /xml-rpc with format string specifiers in the (1) username or (2) password portion of base64-encoded data on the "Authorization: Basic" HTTP header line.
7.5 High
CVSS2