HTTPDX.Tolog.Format.String

Release DateJan 21, 2010
SeverityHigh
ImpactSystem compromise or denial of service
DescriptionThis indicates a possible attack against a format-string vulnerability in the HTTP service of HTTPDX HTTP server.

This vulnerability is due to the software's inability to properly handle specially crafted HTTP requests containing format specifiers. A remote attacker may exploit this to cause memory corruption or arbitrary code execution.
Affected ProductsHTTPDX server 1.5 and prior versions
Recommended ActionsCurrently we are not aware of any officially supplied patch for this issue.
Reference/shttp://www.vupen.com/english/advisories/2009/3312
Reference: VID-18099