oss-sec mailing list archives

Re: plone, rrdtool, zenoss bugs


From: Henri Salo <henri () nerv fi>
Date: Fri, 24 May 2013 10:58:33 +0300

On Fri, May 24, 2013 at 01:37:59AM -0600, Kurt Seifried wrote:
Ho likely is an attacker to be able to pass a format string to it though?

Hard to say how many and which applications are using this library with user
input. At least original reporter pointed out Zenoss-case. I can find out if
there is others if that is needed, but obviously it's impossible to list all use
cases.

---
Henri Salo

Attachment: signature.asc
Description: Digital signature


Current thread: