CVE-2004-0980
published 2005-02-09CVE-2004-0980: Format string vulnerability in ez-ipupdate.c for ez-ipupdate 3.0.10 through 3.0.11b8, when running in daemon mode with certain service types in use, allows…
PriorityP338critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
3.82%
89.0th percentile
Format string vulnerability in ez-ipupdate.c for ez-ipupdate 3.0.10 through 3.0.11b8, when running in daemon mode with certain service types in use, allows remote servers to execute arbitrary code.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| angus_mackay | ez-ipupdate | — | — |
| angus_mackay | ez-ipupdate | — | — |
| angus_mackay | ez-ipupdate | >= 0 < 3.0.11b8-8 | 3.0.11b8-8 |
| debian | debian_linux | — | — |
| debian | ez-ipupdate | < ez-ipupdate 3.0.11b8-8 (bullseye) | ez-ipupdate 3.0.11b8-8 (bullseye) |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g38j-89cg-fgfg: Format string vulnerability in ez-ipupdate
ghsa_unreviewed·2022-04-29
CVE-2004-0980 [HIGH] GHSA-g38j-89cg-fgfg: Format string vulnerability in ez-ipupdate
Format string vulnerability in ez-ipupdate.c for ez-ipupdate 3.0.10 through 3.0.11b8, when running in daemon mode with certain service types in use, allows remote servers to execute arbitrary code.
OSV
CVE-2004-0980: Format string vulnerability in ez-ipupdate
osv·2005-02-09·CVSS 10.0
CVE-2004-0980 [CRITICAL] CVE-2004-0980: Format string vulnerability in ez-ipupdate
Format string vulnerability in ez-ipupdate.c for ez-ipupdate 3.0.10 through 3.0.11b8, when running in daemon mode with certain service types in use, allows remote servers to execute arbitrary code.
Debian
CVE-2004-0980: ez-ipupdate - Format string vulnerability in ez-ipupdate.c for ez-ipupdate 3.0.10 through 3.0....
vendor_debian·2004·CVSS 10.0
CVE-2004-0980 [CRITICAL] CVE-2004-0980: ez-ipupdate - Format string vulnerability in ez-ipupdate.c for ez-ipupdate 3.0.10 through 3.0....
Format string vulnerability in ez-ipupdate.c for ez-ipupdate 3.0.10 through 3.0.11b8, when running in daemon mode with certain service types in use, allows remote servers to execute arbitrary code.
Scope: local
bullseye: resolved (fixed in 3.0.11b8-8)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/028590.htmlhttp://secunia.com/advisories/13167/http://www.debian.org/security/2004/dsa-592http://www.gentoo.org/security/en/glsa/glsa-200411-20.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2004:129http://www.securityfocus.com/bid/11657https://exchange.xforce.ibmcloud.com/vulnerabilities/18032http://lists.grok.org.uk/pipermail/full-disclosure/2004-November/028590.htmlhttp://secunia.com/advisories/13167/http://www.debian.org/security/2004/dsa-592http://www.gentoo.org/security/en/glsa/glsa-200411-20.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2004:129http://www.securityfocus.com/bid/11657https://exchange.xforce.ibmcloud.com/vulnerabilities/18032
2005-02-09
Published