CVE-2003-0671
 
Severity Score
7.2
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Format string vulnerability in tcpflow, when used in a setuid context, allows local users to execute arbitrary code via the device name argument, as demonstrated in Sustworks IPNetSentryX and IPNetMonitorX the setuid program RunTCPFlow.
Vulnerabilidad de cadena de formato en tcpflow, cuando se usa en un contexto setuid, permite a usuarios locales ejecutar código arbitrario mediante el argumento de nombre de dispositivo, como se ha demostrado con Sustworks IPNetSentryX e IPNetMonitorX usando el progarma ayudante RunTCPFlow.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2003-08-07 CVE Reserved
- 2003-08-14 CVE Published
- 2023-03-08 EPSS Updated
- 2024-09-17 CVE Updated
- 2024-09-17 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
http://www.atstake.com/research/advisories/2003/a080703-1.txt | 2024-09-17 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.atstake.com/research/advisories/2003/a080703-2.txt | 2008-09-10 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Jeremy Elson Search vendor "Jeremy Elson" | Tcpflow Search vendor "Jeremy Elson" for product "Tcpflow" | 0.10 Search vendor "Jeremy Elson" for product "Tcpflow" and version "0.10" | - |
Affected
| ||||||
Jeremy Elson Search vendor "Jeremy Elson" | Tcpflow Search vendor "Jeremy Elson" for product "Tcpflow" | 0.11 Search vendor "Jeremy Elson" for product "Tcpflow" and version "0.11" | - |
Affected
| ||||||
Jeremy Elson Search vendor "Jeremy Elson" | Tcpflow Search vendor "Jeremy Elson" for product "Tcpflow" | 0.12 Search vendor "Jeremy Elson" for product "Tcpflow" and version "0.12" | - |
Affected
| ||||||
Jeremy Elson Search vendor "Jeremy Elson" | Tcpflow Search vendor "Jeremy Elson" for product "Tcpflow" | 0.20 Search vendor "Jeremy Elson" for product "Tcpflow" and version "0.20" | - |
Affected
|