7.2

CVE-2004-0172

Heap-based buffer overflow in the search_for_command function of ltrace 0.3.10, if it is installed setuid, could allow local users to execute arbitrary code via a long filename.  NOTE: It is unclear whether there are any packages that install ltrace as a setuid program, so this candidate might be REJECTed.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Juan CespedesLtrace Version0.3.10
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.48% 0.374
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/011600.html
http://lists.grok.org.uk/pipermail/full-disclosure/2003-October/011610.html
http://securitytracker.com/id?1007896
http://www.securityfocus.com/bid/8790
Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/13389