7.5

CVE-2006-3120

Format string vulnerability in Brian Wotring Osiris before 4.2.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via unspecified attack vectors related to the logging functions.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Brian WotringOsiris Version4.0.0
Brian WotringOsiris Version4.0.1
Brian WotringOsiris Version4.0.3
Brian WotringOsiris Version4.0.5
Brian WotringOsiris Version4.0.6
Brian WotringOsiris Version4.0.7
Brian WotringOsiris Version4.0.8
Brian WotringOsiris Version4.1
Brian WotringOsiris Version4.1.1
Brian WotringOsiris Version4.1.2
Brian WotringOsiris Version4.1.3
Brian WotringOsiris Version4.1.4
Brian WotringOsiris Version4.1.5
Brian WotringOsiris Version4.1.7
Brian WotringOsiris Version4.1.8
Brian WotringOsiris Version4.1.9
Brian WotringOsiris Version4.2.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.13% 0.862
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://osiris.shmoo.com/ChangeLog
http://osiris.shmoo.com/download.html
Patch
http://secunia.com/advisories/21257
http://secunia.com/advisories/21265
http://www.debian.org/security/2006/dsa-1129
Patch
Vendor Advisory
http://www.osvdb.org/27645
http://www.securityfocus.com/bid/19213
http://www.vupen.com/english/advisories/2006/3072