CVE Vulnerabilities

CVE-2001-0913

Published: Nov 22, 2001 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Format string vulnerability in Network Solutions Rwhoisd 1.5.7.2 and earlier, when using syslog, allows remote attackers to corrupt memory and possibly execute arbitrary code via a rwhois request that contains format specifiers.

Affected Software

NameVendorStart VersionEnd Version
RwhoisdNetwork_solutions1.5 (including)1.5 (including)
RwhoisdNetwork_solutions1.5.1a (including)1.5.1a (including)
RwhoisdNetwork_solutions1.5.2 (including)1.5.2 (including)
RwhoisdNetwork_solutions1.5.3 (including)1.5.3 (including)
RwhoisdNetwork_solutions1.5.5 (including)1.5.5 (including)
RwhoisdNetwork_solutions1.5.6 (including)1.5.6 (including)
RwhoisdNetwork_solutions1.5.7 (including)1.5.7 (including)
RwhoisdNetwork_solutions1.5.7.1 (including)1.5.7.1 (including)
RwhoisdNetwork_solutions1.5.7.2 (including)1.5.7.2 (including)

References