10
CVSSv2

CVE-2004-0354

Published: 23/11/2004 Updated: 11/07/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Multiple format string vulnerabilities in GNU Anubis 3.6.0 up to and including 3.6.2, 3.9.92 and 3.9.93 allow remote malicious users to execute arbitrary code via format string specifiers in strings passed to (1) the info function in log.c, (2) the anubis_error function in errs.c, or (3) the ssl_error function in ssl.c.

Vulnerable Product Search on Vulmon Subscribe to Product

gnu anubis 3.6.0

gnu anubis 3.6.1

gnu anubis 3.6.2

gnu anubis 3.9.92

gnu anubis 3.9.93

Exploits

source: wwwsecurityfocuscom/bid/9772/info GNU Anubis has been reported prone to multiple buffer overflow and format string vulnerabilities It has been conjectured that a remote attacker may potentially exploit these vulnerabilities to have arbitrary code executed in the context of the Anubis software The buffer overflow vulnerabilities ...