5
CVE-2004-1484
- EPSS 7.29%
- Veröffentlicht 31.12.2004 05:00:00
- Zuletzt bearbeitet 16.06.2026 22:07:47
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Format string vulnerability in the _msg function in error.c in socat 1.4.0.3 and earlier, when used as an HTTP proxy client and run with the -ly option, allows remote attackers or local users to execute arbitrary code via format string specifiers in a syslog message.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 7.29% | 0.936 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:P/A:N
|
http://secunia.com/advisories/12936/
http://www.dest-unreach.org/socat/advisory/socat-adv-1.html
http://www.gentoo.org/security/en/glsa/glsa-200410-26.xml
http://www.nosystem.com.ar/advisories/advisory-07.txt
http://www.securityfocus.com/bid/11505
https://exchange.xforce.ibmcloud.com/vulnerabilities/17822