Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2008-6519

Overview

Vulnerability Score 10.0 10.0
CVE Id CVE-2008-6519
Last Modified 25 Mar 2009 12:00:00
Published 25 Mar 2009 02:30:00
Confidentiality Impact COMPLETE COMPLETE
Integrity Impact COMPLETE COMPLETE
Availability Impact COMPLETE COMPLETE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2008-6519

Summary

Format string vulnerability in Xitami Web Server 2.2a through 2.5c2, and possibly other versions, allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via format string specifiers in a Long Running Web Process (LRWP) request, which triggers incorrect logging code involving the sendfmt function in the SMT kernel.

Vulnerable Systems

Application

  • Imatix Xitami 2.2a

  • Imatix Xitami 2.4

  • Imatix Xitami 2.4d7

  • Imatix Xitami 2.5

  • Imatix Xitami 2.5c2


References

XF - xitami-lrwp-requestlogging-code-execution(41644)

BID - 28603

MILW0RM - 5354

MISC - http://www.bratax.be/advisories/b013.html


Last Updated: 27 May 2016 10:49:13