PT-2004-1645 · Tripwire · Tripwire

Published

2004-06-08

·

Updated

2017-07-11

·

CVE-2004-0536

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Tripwire commercial versions 4.0.1 and earlier Tripwire open source versions 2.3.1 and earlier
Description The issue allows local users to gain privileges via format string specifiers in a file name, which is used in the generation of an email report. This occurs due to a format string vulnerability.
Recommendations For Tripwire commercial versions 4.0.1 and earlier, consider updating to a version later than 4.0.1 to resolve the issue. For Tripwire open source versions 2.3.1 and earlier, consider updating to a version later than 2.3.1 to resolve the issue. As a temporary workaround, consider restricting the use of format string specifiers in file names to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-0536

Affected Products

Tripwire