Linux.LCDproc.Parse.Code.Execution
Description
This indicates an attack attempt against a buffer-overflow vulnerability in LCDProc.
The vulnerability is caused by an error when the parse_all_client_messages function handles a malicious argument. It allows a remote attacker to execute
arbitrary code via sending a crafted request from the client.
Affected Products
LCDProc 4.4 and earlier versions
Impact
System Compromise: Remote attackers can gain control of vulnerable systems.
Recommended Actions
Apply the patch suppied by the vendor:
http://lcdproc.omnipotent.net/download/lcdproc-0.4.5.tar.gz
Telemetry
Coverage
IPS (Regular DB) | |
IPS (Extended DB) |