CVE Vulnerabilities

CVE-2003-0671

Published: Aug 27, 2003 | Modified: Sep 10, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Format string vulnerability in tcpflow, when used in a setuid context, allows local users to execute arbitrary code via the device name argument, as demonstrated in Sustworks IPNetSentryX and IPNetMonitorX the setuid program RunTCPFlow.

Affected Software

Name Vendor Start Version End Version
Tcpflow Jeremy_elson 0.10 0.10
Tcpflow Jeremy_elson 0.11 0.11
Tcpflow Jeremy_elson 0.12 0.12
Tcpflow Jeremy_elson 0.20 0.20

References