5

CVE-2004-1484

Exploit
Format string vulnerability in the _msg function in error.c in socat 1.4.0.3 and earlier, when used as an HTTP proxy client and run with the -ly option, allows remote attackers or local users to execute arbitrary code via format string specifiers in a syslog message.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Socat ≫ Socat Version 1.0.3.0
Socat ≫ Socat Version 1.0.4.0
Socat ≫ Socat Version 1.0.4.1
Socat ≫ Socat Version 1.0.4.2
Socat ≫ Socat Version 1.1.0.0
Socat ≫ Socat Version 1.1.0.1
Socat ≫ Socat Version 1.2.0.0
Socat ≫ Socat Version 1.3.0.0
Socat ≫ Socat Version 1.3.0.1
Socat ≫ Socat Version 1.3.1.0
Socat ≫ Socat Version 1.3.2.0
Socat ≫ Socat Version 1.3.2.1
Socat ≫ Socat Version 1.3.2.2
Socat ≫ Socat Version 1.4.0.0
Socat ≫ Socat Version 1.4.0.1
Socat ≫ Socat Version 1.4.0.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 7.29% 0.936
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/12936/
Patch
Vendor Advisory
http://www.dest-unreach.org/socat/advisory/socat-adv-1.html
Vendor Advisory
http://www.gentoo.org/security/en/glsa/glsa-200410-26.xml
Patch
Vendor Advisory
http://www.nosystem.com.ar/advisories/advisory-07.txt
Patch
Vendor Advisory
Exploit
http://www.securityfocus.com/bid/11505
Patch
Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/17822