PT-2004-1645 · Tripwire · Tripwire
Published
2004-06-08
·
Updated
2017-07-11
·
CVE-2004-0536
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Tripwire commercial versions 4.0.1 and earlier
Tripwire open source versions 2.3.1 and earlier
Description
The issue allows local users to gain privileges via format string specifiers in a file name, which is used in the generation of an email report. This occurs due to a format string vulnerability.
Recommendations
For Tripwire commercial versions 4.0.1 and earlier, consider updating to a version later than 4.0.1 to resolve the issue.
For Tripwire open source versions 2.3.1 and earlier, consider updating to a version later than 2.3.1 to resolve the issue.
As a temporary workaround, consider restricting the use of format string specifiers in file names to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tripwire