VICE监视内存转储文件格式串漏洞

漏洞信息详情

VICE监视内存转储文件格式串漏洞

漏洞简介

VICE 1.6到1.14版本的显示器“内存转储”命令存在格式化字符串漏洞。本地用户借助输出字符串里的格式字符串说明符导致服务拒绝(仿真器崩溃)和可能执行任意代码。

漏洞公告

Spiro Trikaliotis , a developer for the VICE project, supplied the following supported patch:
http://downloads.securityfocus.com/vulnerabilities/patches/vice-1.14-mon-vuln.patch
VICE version 1.15 has been released and resolves this issue.
VICE VICE 1.10
@gmx.de>

VICE VICE 1.11

VICE VICE 1.12

VICE VICE 1.13

VICE VICE 1.14

VICE VICE 1.6

VICE VICE 1.7

VICE VICE 1.8

VICE VICE 1.9

参考网址

来源: BID
名称: 10543
链接:http://www.securityfocus.com/bid/10543

来源: XF
名称: vice-memory-dump-format-string(16404)
链接:http://xforce.iss.net/xforce/xfdb/16404

来源: BUGTRAQ
名称: 20040614 VICE emulator format string vulnerability
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=108723630730487&w=2

受影响实体

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享