PT-2004-1110 · Sus · Sus

Published

2004-09-14

·

Updated

2017-07-11

·

CVE-2004-1469

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SUS versions 2.0.2 through 2.0.5 SUS version 2.0.2 and earlier
Description The issue is related to a format string vulnerability in the log function. This vulnerability allows local users to execute arbitrary code via format string specifiers in a command line argument that is passed directly to syslog. The vulnerability can lead to a breach of confidentiality, integrity, and availability of protected information. It can be exploited locally.
Recommendations For SUS versions 2.0.2 through 2.0.5, update to version 2.0.6 or later to resolve the issue. For SUS version 2.0.2 and earlier, update to version 2.0.6 or later to resolve the issue. As a temporary workaround, consider restricting access to the log function to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-09465
CVE-2004-1469

Affected Products

Sus