CVE-2007-1251 Information

Description

Format string vulnerability in the new_warning function in ntserv/warning.c for Netrek Vanilla Server 2.12.0 when EVENTLOG is enabled allows remote attackers to cause a denial of service (crash) or execute arbitrary code via format string specifiers in the message handling.

Reference

http://aluigi.altervista.org/adv/netrekfs-adv.txt http://secunia.com/advisories/24357 http://sourceforge.net/project/shownotes.php?release_id=490561 http://www.securityfocus.com/archive/1/461755/100/0/threaded http://www.securityfocus.com/bid/22786 http://www.vupen.com/english/advisories/2007/0815 https://exchange.xforce.ibmcloud.com/vulnerabilities/32777

Share on: