CVE-2004-0536

high

Description

Format string vulnerability in Tripwire commercial 4.0.1 and earlier, including 2.4, and open source 2.3.1 and earlier, allows local users to gain privileges via format string specifiers in a file name, which is used in the generation of an email report.

References

https://exchange.xforce.ibmcloud.com/vulnerabilities/16309

http://www.securityfocus.com/bid/10454

http://www.redhat.com/support/errata/RHSA-2004-244.html

http://security.gentoo.org/glsa/glsa-200406-02.xml

http://marc.info/?l=bugtraq&m=108630983009228&w=2

http://marc.info/?l=bugtraq&m=108627481507249&w=2

Details

Source: Mitre, NVD

Published: 2004-08-06

Updated: 2017-07-11

Risk Information

CVSS v2

Base Score: 7.2

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 7.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High