PT-2002-1575 · Internet Systems Consortium · Inn
Published
2002-06-11
·
Updated
2008-09-05
·
CVE-2002-0525
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
INN versions 2.2.3 and earlier
Description
The issue allows local users and remote malicious NNTP servers to gain privileges. This is achieved through format string specifiers in NNTP responses.
Recommendations
For INN versions 2.2.3 and earlier, at the moment, there is no information about a newer version that contains a fix for this issue.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Inn