10
CVSSv2

CVE-2004-0451

Published: 06/12/2004 Updated: 11/07/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Multiple format string vulnerabilities in the (1) logquit, (2) logerr, or (3) loginfo functions in Software Upgrade Protocol (SUP) allows remote malicious users to execute arbitrary code via format string specifiers in messages that are logged by syslog.

Vulnerable Product Search on Vulmon Subscribe to Product

sup sup 1.8

debian debian linux 3.0

Vendor Advisories

jaguar@felinemenaceorg discovered a format string vulnerability in sup, a set of programs to synchronize collections of files across a number of machines, whereby a remote attacker could potentially cause arbitrary code to be executed with the privileges of the supfilesrv process (this process does not run automatically by default) CAN-2004-0451: ...