// For flags

CVE-2003-0671

 

Severity Score

7.2
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Format string vulnerability in tcpflow, when used in a setuid context, allows local users to execute arbitrary code via the device name argument, as demonstrated in Sustworks IPNetSentryX and IPNetMonitorX the setuid program RunTCPFlow.

Vulnerabilidad de cadena de formato en tcpflow, cuando se usa en un contexto setuid, permite a usuarios locales ejecutar código arbitrario mediante el argumento de nombre de dispositivo, como se ha demostrado con Sustworks IPNetSentryX e IPNetMonitorX usando el progarma ayudante RunTCPFlow.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2003-08-07 CVE Reserved
  • 2003-08-14 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-09-17 CVE Updated
  • 2024-09-17 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Jeremy Elson
Search vendor "Jeremy Elson"
Tcpflow
Search vendor "Jeremy Elson" for product "Tcpflow"
0.10
Search vendor "Jeremy Elson" for product "Tcpflow" and version "0.10"
-
Affected
Jeremy Elson
Search vendor "Jeremy Elson"
Tcpflow
Search vendor "Jeremy Elson" for product "Tcpflow"
0.11
Search vendor "Jeremy Elson" for product "Tcpflow" and version "0.11"
-
Affected
Jeremy Elson
Search vendor "Jeremy Elson"
Tcpflow
Search vendor "Jeremy Elson" for product "Tcpflow"
0.12
Search vendor "Jeremy Elson" for product "Tcpflow" and version "0.12"
-
Affected
Jeremy Elson
Search vendor "Jeremy Elson"
Tcpflow
Search vendor "Jeremy Elson" for product "Tcpflow"
0.20
Search vendor "Jeremy Elson" for product "Tcpflow" and version "0.20"
-
Affected