CVE-2002-0501
Format string vulnerability in log_print() function of Posadis DNS server before version m5pre2 allows local users and possibly remote attackers to execute arbitrary code via format strings that are inserted into logging messages.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.27%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Format string vulnerability in log_print() function of Posadis DNS server before version m5pre2 allows local users and possibly remote attackers to execute arbitrary code via format strings that are inserted into logging messages.
- CVSS 2.0
- 7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 1.27% probability · 68th percentile
- CISA KEV
- Not listed
- Affected
- posadis/posadis
- Source
- cve@mitre.org
References
- http://online.securityfocus.com/archive/1/264450Vendor Advisory
- http://sourceforge.net/forum/forum.php?forum_id=165094
- http://www.iss.net/security_center/static/8653.phpVendor Advisory
- http://www.osvdb.org/3516
- http://www.securityfocus.com/bid/4378Patch, Vendor Advisory
- http://online.securityfocus.com/archive/1/264450Vendor Advisory
- http://sourceforge.net/forum/forum.php?forum_id=165094
- http://www.iss.net/security_center/static/8653.phpVendor Advisory
- http://www.osvdb.org/3516
- http://www.securityfocus.com/bid/4378Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.