CVE-2002-0586: High severity AOL Aol Server vulnerability
Published Jun 11, 2002
·Updated
Format string vulnerability in NsPdLog function for the external database driver proxy daemon library (libnspd.a) of AOLServer 3.0 through 3.4.2 allows remote attackers to execute arbitrary code via the Error or Notice parameters.
Affected Software
9 affected components
AOL Aol Server=3.0
AOL Aol Server=3.1
AOL Aol Server=3.2
AOL Aol Server=3.2.1
AOL Aol Server=3.3
AOL Aol Server=3.3.1
AOL Aol Server=3.4
AOL Aol Server=3.4.1
AOL Aol Server=3.4.2
Remediation
Patch Available
Patch Available
Event History
Jun 11, 2002
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-0586?
The severity of CVE-2002-0586 is high due to the potential for remote code execution.
2
How do I fix CVE-2002-0586?
To fix CVE-2002-0586, update AOLServer to a patched version beyond 3.4.2.
3
What versions of AOLServer are affected by CVE-2002-0586?
CVE-2002-0586 affects AOLServer versions 3.0, 3.1, 3.2, 3.2.1, 3.3, 3.3.1, 3.4, 3.4.1, and 3.4.2.
4
What type of vulnerability is CVE-2002-0586?
CVE-2002-0586 is a format string vulnerability in the Ns_PdLog function.
5
Can CVE-2002-0586 be exploited remotely?
Yes, CVE-2002-0586 can be exploited remotely by attackers leveraging the Error or Notice parameters.