>> BitDefender Client Professional Plus Settings Handling Local Format String Vulnerability
Title : BitDefender Client Professional Plus Settings Handling Local Format String Vulnerability VUPEN ID : VUPEN/ADV-2007-0253 CVE ID : CVE-2007-0391
Rated as : Moderate Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2007-01-19
Technical Description
A vulnerability has been identified in BitDefender Client Professional Plus, which could be exploited by local attackers to cause a denial of service or obtain elevated privileges. This issue is due to a format string error in the logging routines when handling malformed scanning settings, which could be exploited by malicious users to crash an affected application or execute arbitrary commands via a specially crafted scan job.