CVE-2002-0586

critical

Description

Format string vulnerability in Ns_PdLog function for the external database driver proxy daemon library (libnspd.a) of AOLServer 3.0 through 3.4.2 allows remote attackers to execute arbitrary code via the Error or Notice parameters.

References

http://www.securityfocus.com/bid/4535

http://www.iss.net/security_center/static/8860.php

http://sourceforge.net/tracker/index.php?func=detail&aid=533141&group_id=3152&atid=303152

http://archives.neohapsis.com/archives/bugtraq/2002-04/0195.html

Details

Source: Mitre, NVD

Published: 2002-06-18

Updated: 2008-09-05

Risk Information

CVSS v2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Severity: High

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical