Executive Summary
| Informations | |||
|---|---|---|---|
| Name | MDVSA-2009:234-2 | First vendor Publication | 2009-12-05 |
| Vendor | Mandriva | Last vendor Modification | 2009-12-05 |
| Severity (Vendor) | N/A | Revision | N/A |
Security-Database Scoring CVSS v2
| Cvss vector : (AV:N/AC:L/Au:N/C:P/I:P/A:P) | |||
|---|---|---|---|
| Cvss Base Score | 7.5 | Attack Range | Network |
| Cvss Impact Score | 6.4 | Attack Complexity | Low |
| Cvss Expoit Score | 10 | Authentification | None Required |
| Calculate full CVSS 2.0 Vectors scores | |||
Detail
Multiple vulnerabilities was discovered and corrected in silc-toolkit: Multiple format string vulnerabilities in lib/silcclient/client_entry.c in Secure Internet Live Conferencing (SILC) Toolkit before 1.1.10, and SILC Client before 1.1.8, allow remote attackers to execute arbitrary code via format string specifiers in a nickname field, related to the (1) silc_client_add_client, (2) silc_client_update_client, and (3) silc_client_nickname_format functions (CVE-2009-3051). The silc_asn1_encoder function in lib/silcasn1/silcasn1_encode.c in Secure Internet Live Conferencing (SILC) Toolkit before 1.1.8 allows remote attackers to overwrite a stack location and possibly execute arbitrary code via a crafted OID value, related to incorrect use of a %lu format string (CVE-2008-7159). The silc_http_server_parse function in lib/silchttp/silchttpserver.c in the internal HTTP server in silcd in Secure Internet Live Conferencing (SILC) Toolkit before 1.1.9 allows remote attackers to overwrite a stack location and possibly execute arbitrary code via a crafted Content-Length header, related to incorrect use of a %lu format string (CVE-2008-7160). Multiple format string vulnerabilities in lib/silcclient/command.c in Secure Internet Live Conferencing (SILC) Toolkit before 1.1.10, and SILC Client 1.1.8 and earlier, allow remote attackers to execute arbitrary code via format string specifiers in a channel name, related to (1) silc_client_command_topic, (2) silc_client_command_kick, (3) silc_client_command_leave, and (4) silc_client_command_users (CVE-2009-3163). This update provides a solution to these vulnerabilities. Update: Packages for MES5 was not provided previousely, this update addresses this problem. Packages for 2008.0 are being provided due to extended support for Corporate products. |
Original Source
| Url : http://www.mandriva.com/security/advisories?name=MDVSA-2009:234-2 |
CWE : Common Weakness Enumeration
| id | Name |
|---|---|
| CWE-134 | Uncontrolled Format String |
CPE : Common Platform Enumeration
| Type | Description | Count |
|---|---|---|
| Application | 7 | |
| Application | 9 |
Open Source Vulnerability Database (OSVDB)
| id | Description |
|---|---|
| 58033 | SILC Toolkit / Client lib/silcclient/command.c Multiple Function Format String |
| 57831 | SILC Server / Toolkit silchttpserver.c Format String Memory Corruption |
| 57830 | SILC Server / Toolkit silcasn1_encode.c Format String Memory Corruption |
| 56761 | SILC Client lib/silcclient/client_entries.c Format String |

MDVSA-2009:234-2
(High)
(Medium)





