Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2004-0623


Format string vulnerability in misc.c in GNU GNATS 4.00 may allow remote attackers to execute arbitrary code via format string specifiers in a string that gets logged by syslog.


Published

2004-12-06T05:00:00.000

Last Modified

2025-04-03T01:03:51.193

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 10.0 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

10.0

Impact Score

10.0

Weaknesses
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application gnu gnats 3.0_02 Yes
Application gnu gnats 3.2 Yes
Application gnu gnats 3.14b Yes
Application gnu gnats 3.113 Yes
Application gnu gnats 3.113.1 Yes
Application gnu gnats 3.113.1.6 Yes
Application gnu gnats 4.0 Yes

References