PT-2004-1110 · Sus · Sus

Publicado

2004-09-14

·

Atualizado

2017-07-11

·

CVE-2004-1469

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SUS versions 2.0.2 through 2.0.5 SUS version 2.0.2 and earlier
Description The issue is related to a format string vulnerability in the log function. This vulnerability allows local users to execute arbitrary code via format string specifiers in a command line argument that is passed directly to syslog. The vulnerability can lead to a breach of confidentiality, integrity, and availability of protected information. It can be exploited locally.
Recommendations For SUS versions 2.0.2 through 2.0.5, update to version 2.0.6 or later to resolve the issue. For SUS version 2.0.2 and earlier, update to version 2.0.6 or later to resolve the issue. As a temporary workaround, consider restricting access to the log function to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2015-09465
CVE-2004-1469

Produtos afetados

Sus