Format string vulnerability in the log function in SUS 2.0.2, and other versions before 2.0.6, allows local users to execute arbitrary code via format string specifiers in a command line argument that is passed directly to syslog.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Sus | Peter_d._gray | 2.0 (including) | 2.0 (including) |
| Sus | Peter_d._gray | 2.0.1 (including) | 2.0.1 (including) |