Vulnerability Name: | CVE-2004-0451 (CCN-16459) | ||||||||
Assigned: | 2004-06-19 | ||||||||
Published: | 2004-06-19 | ||||||||
Updated: | 2017-07-11 | ||||||||
Summary: | Multiple format string vulnerabilities in the (1) logquit, (2) logerr, or (3) loginfo functions in Software Upgrade Protocol (SUP) allows remote attackers to execute arbitrary code via format string specifiers in messages that are logged by syslog. | ||||||||
CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2004-0451 Source: CCN Type: SECTRACK ID: 1010539 sup Logging Function Format String Errors May Let Remote Users Execute Arbitrary Code Source: SECTRACK Type: UNKNOWN 1010539 Source: DEBIAN Type: Patch, Vendor Advisory DSA-521 Source: DEBIAN Type: DSA-521 sup -- format string vulnerability Source: CCN Type: OSVDB ID: 7193 SUP Logging Command Execution Source: BID Type: Patch, Vendor Advisory 10571 Source: CCN Type: BID-10571 Sup Remote Syslog Format String Vulnerability Source: XF Type: UNKNOWN sup-format-string(16459) Source: XF Type: UNKNOWN sup-format-string(16459) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: ![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |