CVE Database
/

CVE-2003-0671

Back to search

CVE-2003-0671

Published: Aug 14, 2003

Modified: Sep 17, 2024

PUBLISHED

Description

Format string vulnerability in tcpflow, when used in a setuid context, allows local users to execute arbitrary code via the device name argument, as demonstrated in Sustworks IPNetSentryX and IPNetMonitorX the setuid program RunTCPFlow.

VendorProductVersions

n/a

n/a

affected
n/a

References

A080703-1
vendor-advisory
x_refsource_ATSTAKE
A080703-2
vendor-advisory
x_refsource_ATSTAKE

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now