HIGH
Format string vulnerability in tcpflow, when used in a setuid context, allows local users to execute arbitrary code via the device name argument, as demonstrated in Sustworks IPNetSentryX and IPNetMonitorX the setuid program RunTCPFlow
Published Aug 14, 2003
7.2
HIGHCVSS 2.0
EPSS 0.55%
Description
Affected products
Remediation
Metrics
References (2)
Change history (0)
No recorded changes yet.