Format string vulnerability in the logging functionality in BitDefender AntiVirus 7.2 through 9 allows remote attackers to cause a denial of service and possibly execute arbitrary code via format string specifiers in file or directory name.
References
Link | Resource |
---|---|
http://shadock.net/secubox/BitDefenderLoggingFunc.html | Broken Link |
http://kb.bitdefender.com/KB261-en--Filename-Format-String-Vulnerability.html | Broken Link |
http://www.securityfocus.com/bid/14968 | Third Party Advisory |
http://secunia.com/advisories/16991 | Permissions Required |
http://securityreason.com/securityalert/45 | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2005-10-05 16:02
Updated : 2016-09-30 07:33
NVD link : CVE-2005-3154
Mitre link : CVE-2005-3154
JSON object : View
CWE
CWE-134
Use of Externally-Controlled Format String
Products Affected
softwin
- bitdefender