CVE Vulnerabilities

CVE-2004-0536

Published: Aug 06, 2004 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Format string vulnerability in Tripwire commercial 4.0.1 and earlier, including 2.4, and open source 2.3.1 and earlier, allows local users to gain privileges via format string specifiers in a file name, which is used in the generation of an email report.

Affected Software

NameVendorStart VersionEnd Version
TripwireTripwire2.2.1 (including)2.2.1 (including)
TripwireTripwire2.3.0 (including)2.3.0 (including)
TripwireTripwire2.3.1 (including)2.3.1 (including)
TripwireTripwire2.3.1.2 (including)2.3.1.2 (including)
TripwireTripwire2.4.0 (including)2.4.0 (including)
TripwireTripwire2.4.2 (including)2.4.2 (including)
TripwireTripwire3.0 (including)3.0 (including)
TripwireTripwire3.0.1 (including)3.0.1 (including)
TripwireTripwire4.0 (including)4.0 (including)
TripwireTripwire4.0.1 (including)4.0.1 (including)
TripwireTripwire4.1 (including)4.1 (including)
Red Hat Enterprise Linux AS (Advanced Server) version 2.1RedHat*
Red Hat Enterprise Linux ES version 2.1RedHat*
Red Hat Enterprise Linux WS version 2.1RedHat*
TripwireUbuntudapper*
TripwireUbuntudevel*
TripwireUbuntuedgy*
TripwireUbuntufeisty*

References