Sup

Sup

2 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 3.66%
  • Published 06.12.2004 05:00:00
  • Last modified 03.04.2025 01:03:51

Multiple format string vulnerabilities in the (1) logquit, (2) logerr, or (3) loginfo functions in Software Upgrade Protocol (SUP) allows remote attackers to execute arbitrary code via format string specifiers in messages that are logged by syslog.

  • EPSS 0.06%
  • Published 27.08.2003 04:00:00
  • Last modified 03.04.2025 01:03:51

sup 1.8 and earlier does not properly create temporary files, which allows local users to overwrite arbitrary files.