CVE-2004-0623

4 documents4 sources
Severity
10.0CRITICAL
EPSS
3.4%
top 12.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 6
Latest updateApr 29

Description

Format string vulnerability in misc.c in GNU GNATS 4.00 may allow remote attackers to execute arbitrary code via format string specifiers in a string that gets logged by syslog.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages1 packages

NVDgnu/gnats7 versions+6

Patches

🔴Vulnerability Details

2
GHSA
GHSA-694j-gvq7-rqg6: Format string vulnerability in misc2022-04-29
CVEList
CVE-2004-0623: Format string vulnerability in misc2004-06-30

💥Exploits & PoCs

1
Exploit-DB
QNX RTOS 6.3.0 - Insecure 'rc.local' Permissions System Crash / Privilege Escalation2006-02-08