CVE Vulnerabilities

CVE-2004-2026

Published: Dec 31, 2004 | Modified: Jul 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Format string vulnerability in the logmsg function in svc.c for Pound 1.5 and earlier allows remote attackers to execute arbitrary code via format string specifiers in syslog messages.

Affected Software

Name Vendor Start Version End Version
Pound Apsis 1.0 (including) 1.0 (including)
Pound Apsis 1.1 (including) 1.1 (including)
Pound Apsis 1.2 (including) 1.2 (including)
Pound Apsis 1.3 (including) 1.3 (including)
Pound Apsis 1.4 (including) 1.4 (including)
Pound Apsis 1.5 (including) 1.5 (including)

References