CVE-2002-0175: Medium severity Avaya Libsafe vulnerability
libsafe 2.0-11 and earlier allows attackers to bypass protection against format string vulnerabilities via format strings that use the "'" and "I" characters, which are implemented in libc but not libsafe.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2002-0175?
CVE-2002-0175 is considered a moderate severity vulnerability that can allow attackers to bypass protections against format string vulnerabilities.
How do I fix CVE-2002-0175?
To fix CVE-2002-0175, you should upgrade to a version of libsafe that is newer than 2.0-11.
Which versions of libsafe are affected by CVE-2002-0175?
CVE-2002-0175 affects versions of libsafe 2.0-11 and earlier, including 1.3.8 and 2.0.5.
What type of attack does CVE-2002-0175 facilitate?
CVE-2002-0175 facilitates format string attacks by allowing specified format strings to bypass libsafe protection.
Is it possible to exploit CVE-2002-0175 remotely?
Yes, CVE-2002-0175 can be exploited remotely if an application does not properly validate input using the affected versions of libsafe.