...
Wiki Markup |
---|
1.) [CVE-2009-1252|http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-1252] results from a violation of this rule. The Network Time Protocol (NTPd), before versions 4.2.4p7 and 4.2.5p74, contains calls to sprintf that allow an exploiter to runexecute arbitrary code by overflowing a character array \[[xorl 2009|AA. C References#xorl 2009]\]. |
...