Security Advisory

CVE-2003-0671

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2003-08-14 04:00:00
Last updated 2024-09-17 03:49:26
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Format string vulnerability in tcpflow, when used in a setuid context, allows local users to execute arbitrary code via the device name argument, as demonstrated in Sustworks IPNetSentryX and IPNetMonitorX the setuid program RunTCPFlow.