icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons icons_061

gpsd < 2.8 gpsd_report() Function Remote Format String

High

Synopsis

The remote host is vulnerable to a remote 'format string' flaw.

Description

The remote host is running GPSD, a daemon that monitors a GPS device and publishes its data over the network.

The remote version of this software is vulnerable to format string attack due to the way it uses the syslog() call. An attacker may exploit this flaw to execute arbitrary code on the remote host.

Solution

Upgrade to gpsd 2.8 or higher.