CVE Vulnerabilities

CVE-2002-0525

Published: Aug 12, 2002 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Format string vulnerabilities in (1) inews or (2) rnews for INN 2.2.3 and earlier allow local users and remote malicious NNTP servers to gain privileges via format string specifiers in NTTP responses.

Affected Software

NameVendorStart VersionEnd Version
InnIsc2.0 (including)2.0 (including)
InnIsc2.1 (including)2.1 (including)
InnIsc2.2 (including)2.2 (including)
InnIsc2.2.1 (including)2.2.1 (including)
InnIsc2.2.2 (including)2.2.2 (including)
InnIsc2.2.3 (including)2.2.3 (including)

References