CVE-2006-5790
published 2006-11-07CVE-2006-5790: Multiple format string vulnerabilities in elogd.c in ELOG 2.6.2 and earlier allow remote attackers to cause a denial of service (crash) and possibly execute…
PriorityP433high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
3.06%
86.0th percentile
Multiple format string vulnerabilities in elogd.c in ELOG 2.6.2 and earlier allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) an entry with an attachment whose name contains format string specifiers (el_submit function), and possibly other vectors in the (2) receive_config, (3) show_rss_feed, (4) show_elog_list, (5) show_logbook_node, and (6) server_loop functions.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| stefan_ritt | elog_web_logbook | <= 2.6.2 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=392016http://secunia.com/advisories/22638http://secunia.com/advisories/23580http://www.debian.org/security/2006/dsa-1242http://www.securityfocus.com/bid/20876http://www.vupen.com/english/advisories/2006/4315https://exchange.xforce.ibmcloud.com/vulnerabilities/29987http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=392016http://secunia.com/advisories/22638http://secunia.com/advisories/23580http://www.debian.org/security/2006/dsa-1242http://www.securityfocus.com/bid/20876http://www.vupen.com/english/advisories/2006/4315https://exchange.xforce.ibmcloud.com/vulnerabilities/29987
2006-11-07
Published