Vulnerability Description
Format string vulnerability in the nm_info_handler function in Network Manager may allow remote attackers to execute arbitrary code via format string specifiers in a Wireless Access Point identifier, which is not properly handled in a syslog call.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gnome | Networkmanager | < 0.4.1 |
References
- http://lwn.net/Alerts/145678/Third Party Advisory
- http://mail.gnome.org/archives/networkmanager-list/2005-July/msg00196.htmlMailing ListVendor Advisory
- http://mail.gnome.org/archives/networkmanager-list/2005-July/msg00197.htmlMailing ListVendor Advisory
- http://lwn.net/Alerts/145678/Third Party Advisory
- http://mail.gnome.org/archives/networkmanager-list/2005-July/msg00196.htmlMailing ListVendor Advisory
- http://mail.gnome.org/archives/networkmanager-list/2005-July/msg00197.htmlMailing ListVendor Advisory
FAQ
What is CVE-2005-2410?
CVE-2005-2410 is a vulnerability with a CVSS score of 7.5 (HIGH). Format string vulnerability in the nm_info_handler function in Network Manager may allow remote attackers to execute arbitrary code via format string specifiers in a Wireless Access Point identifier, ...
How severe is CVE-2005-2410?
CVE-2005-2410 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2005-2410?
Check the references section above for vendor advisories and patch information. Affected products include: Gnome Networkmanager.