First published: Thu Jul 10 2003(Updated: )
cnd.c in mgetty 1.1.28 and earlier does not properly filter non-printable characters and quotes, which may allow remote attackers to execute arbitrary commands via shell metacharacters in (1) caller ID or (2) caller name strings.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Gert Doering Mgetty | <=1.1.28 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.