10
CVSSv2

CVE-2004-0450

Published: 06/08/2004 Updated: 11/07/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Format string vulnerability in the printlog function in log2mail prior to 0.2.5.2 allows local users or remote malicious users to execute arbitrary code via format string specifiers in a logfile monitored by log2mail.

Vulnerable Product Search on Vulmon Subscribe to Product

log2mail log2mail 0.2.5.0

log2mail log2mail 0.2.5.1

log2mail log2mail 0.2.2.2

log2mail log2mail 0.2.5.2

Vendor Advisories

jaguar@felinemenaceorg discovered a format string vulnerability in log2mail, whereby a user able to log a specially crafted message to a logfile monitored by log2mail (for example, via syslog) could cause arbitrary code to be executed with the privileges of the log2mail process By default, this process runs as user 'log2mail', which is a member o ...