Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Format string vulnerability in PFinger 0.7.5 through 0.7.7 allows remote attackers to execute arbitrary code via format string specifiers in a .plan file.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
PFinger远程格式化串溢出漏洞
Vulnerability Description
PFinger是标准的Finger协议守护程序,同时也支持PIP协议,该守护程序缺省以"nobody"身份运行,还包含一个图形化的客户端。 其服务器程序和客户端程序都存在一个安全问题,可能导致执行任意代码。 与某个用户相关的Finger数据,包括".plan"文件,都被作为格式串传递给"printf"函数调用,通过精心构造这些数据,就可能在服务器端或客户端执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A