[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <200512012210.00213.fdlist@digitaloffense.net>
Date: Fri Dec 2 04:10:18 2005
From: fdlist at digitaloffense.net (H D Moore)
Subject: Webmin miniserv.pl format string vulnerability
As many folks have pointed out and consistent with the recent Dyad
advisory, these bugs are indeed exploitable. I only mention this because
a reporter quoted someone who quoted my original message and then used it
to downplay the severity of the problem.
$ perl -e 'printf("%2918905856\$vs")'
-HD
On Tuesday 29 November 2005 11:15, H D Moore wrote:
> On Tuesday 29 November 2005 04:07, advisory@...dsecurity.com wrote:
> > [snip ] so so if remote code execution is successful, it would
> > lead to a full remote root compromise in a standard configuration.
Powered by blists - more mailing lists