SMStools vulnerabilities in release before 1.4.8

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Hello,
    Stefan Frings' SMStools have a couple of string format 
vulnerabilities affecting many old releases. Impact involves arbitrary 
command injection and execution with the privileges of the user running 
'smsd'. Release 1.4.8 (current) is fixing both vulnerabilities, while 
1.4.7 fixes the most trivial one. All SMStools users should upgrade to 
1.4.8 as soon as possible.
See http://www.isis.de/members/~s.frings/smstools/ for details and download.


    C U,
    Marcello Magnifico





[Index of Archives]     [Linux Security]     [Netfilter]     [PHP]     [Yosemite News]     [Linux Kernel]

  Powered by Linux