Skip to main content

Use of Externally-Controlled Format String

CVE-2008-0945

Severity Low
Score 3.5/10

Summary

Format string vulnerability in the logging function in the IM Server (aka IMserve or IMserver) in Ipswitch Instant Messaging (IM) 2.0.8.1 and earlier allows remote authenticated users to cause a denial of service (daemon crash) and possibly have unspecified other impact via format string specifiers in an IP address field.

  • MEDIUM
  • NETWORK
  • SINGLE
  • NONE
  • NONE
  • PARTIAL

CWE-134 - Use of Externally-Controlled Format String

The software uses a function that accepts a format string as an argument, but the format string originates from an external source.

References

Advisory Timeline

  • Published