CVE-2002-0501: High severity Posadis Posadis vulnerability
Published Aug 12, 2002
·Updated
Format string vulnerability in logprint() function of Posadis DNS server before version m5pre2 allows local users and possibly remote attackers to execute arbitrary code via format strings that are inserted into logging messages.
Affected Software
1 affected component
Posadis Posadis=m5pre1
Remediation
Patch Available
Event History
Aug 12, 2002
CVE Published
04:00 AM
Apr 2, 2003
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-0501?
CVE-2002-0501 is considered a critical vulnerability due to its potential to allow arbitrary code execution.
2
How do I fix CVE-2002-0501?
To fix CVE-2002-0501, update your Posadis DNS server to version m5pre2 or later.
3
Who is affected by CVE-2002-0501?
CVE-2002-0501 affects all versions of Posadis DNS server prior to m5pre2.
4
Can CVE-2002-0501 be exploited remotely?
Yes, CVE-2002-0501 can potentially be exploited by remote attackers if they can trigger the logging functionality.
5
What causes CVE-2002-0501?
CVE-2002-0501 is caused by a format string vulnerability in the log_print() function of the Posadis DNS server.