CVE Vulnerabilities

CVE-2003-0671

Published: Aug 27, 2003 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Format string vulnerability in tcpflow, when used in a setuid context, allows local users to execute arbitrary code via the device name argument, as demonstrated in Sustworks IPNetSentryX and IPNetMonitorX the setuid program RunTCPFlow.

Affected Software

NameVendorStart VersionEnd Version
TcpflowJeremy_elson0.10 (including)0.10 (including)
TcpflowJeremy_elson0.11 (including)0.11 (including)
TcpflowJeremy_elson0.12 (including)0.12 (including)
TcpflowJeremy_elson0.20 (including)0.20 (including)

References