Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple format string vulnerabilities in the logger function in netzio.c for Tanne 0.6.17 allows remote attackers to execute arbitrary code via format string specifiers in syslog.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
TANne会话管理Syslog格式串溢出漏洞
Vulnerability Description
TANne是一款开放源码会话管理系统,可确保WEB应用程序开发者可使用实际安全的会话,而不是一般的Cookie或Session-ids,可使用在Unix和Linux操作系统下。 TANne 0.6.17版本在实现日志记录时不正确检查外部输入,远程攻击者可以利用这个漏洞进行格式串兴出攻击,可能以TANne进程权限在系统上执行任意指令。
CVSS Information
N/A
Vulnerability Type
N/A