Vulnerability Description
Format string vulnerability in Logger.cc for Spey 0.3.3 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in a syslog call.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Spey | Spey | 0.3.3 |
Related Weaknesses (CWE)
References
- http://sourceforge.net/forum/forum.php?forum_id=514029
- http://spey.cvs.sourceforge.net/spey/spey/src/Logger.cc?r1=1.5&r2=1.6Exploit
- http://spey.cvs.sourceforge.net/spey/spey/src/Logger.cc?view=log
- http://www.osvdb.org/21327
- http://sourceforge.net/forum/forum.php?forum_id=514029
- http://spey.cvs.sourceforge.net/spey/spey/src/Logger.cc?r1=1.5&r2=1.6Exploit
- http://spey.cvs.sourceforge.net/spey/spey/src/Logger.cc?view=log
- http://www.osvdb.org/21327
FAQ
What is CVE-2005-4846?
CVE-2005-4846 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Format string vulnerability in Logger.cc for Spey 0.3.3 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in a syslog call.
How severe is CVE-2005-4846?
CVE-2005-4846 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2005-4846?
Check the references section above for vendor advisories and patch information. Affected products include: Spey Spey.