CVE Vulnerabilities

CVE-2004-0536

Published: Aug 06, 2004 | Modified: Jul 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

Format string vulnerability in Tripwire commercial 4.0.1 and earlier, including 2.4, and open source 2.3.1 and earlier, allows local users to gain privileges via format string specifiers in a file name, which is used in the generation of an email report.

Affected Software

Name Vendor Start Version End Version
Tripwire Tripwire 2.2.1 (including) 2.2.1 (including)
Tripwire Tripwire 2.3.0 (including) 2.3.0 (including)
Tripwire Tripwire 2.3.1 (including) 2.3.1 (including)
Tripwire Tripwire 2.3.1.2 (including) 2.3.1.2 (including)
Tripwire Tripwire 2.4.0 (including) 2.4.0 (including)
Tripwire Tripwire 2.4.2 (including) 2.4.2 (including)
Tripwire Tripwire 3.0 (including) 3.0 (including)
Tripwire Tripwire 3.0.1 (including) 3.0.1 (including)
Tripwire Tripwire 4.0 (including) 4.0 (including)
Tripwire Tripwire 4.0.1 (including) 4.0.1 (including)
Tripwire Tripwire 4.1 (including) 4.1 (including)
Tripwire Ubuntu dapper *
Tripwire Ubuntu devel *
Tripwire Ubuntu edgy *
Tripwire Ubuntu feisty *
Red Hat Enterprise Linux AS (Advanced Server) version 2.1 RedHat *
Red Hat Enterprise Linux ES version 2.1 RedHat *
Red Hat Enterprise Linux WS version 2.1 RedHat *

References