Release DateJan 05, 2012 |
Severityhigh |
ImpactSystem Compromise: Remote attackers can gain control of vulnerable systems. |
DescriptionThis indicates a possible exploit of a Format String vulnerability in LCDProc.The vulnerability is due to an error in test_func_func. It may allow remote attackers to execute arbitrary code by entering format string specifiers in the str variable. |
Affected ProductsLCDProc LCDProc 4.4 and earlier versions. |
Recommended ActionsUpgrade to LCDProc LCDProc 4.4 |
Coverage IPS
VCM |
Reference/shttp://www.securityfocus.com/bid/10085 (BugTraq) |