Vulnerability Details CVE-2003-0671
Format string vulnerability in tcpflow, when used in a setuid context, allows local users to execute arbitrary code via the device name argument, as demonstrated in Sustworks IPNetSentryX and IPNetMonitorX the setuid program RunTCPFlow.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 19.2%
CVSS Severity
CVSS v2 Score 7.2
Products affected by CVE-2003-0671
-
cpe:2.3:a:jeremy_elson:tcpflow:0.10
-
cpe:2.3:a:jeremy_elson:tcpflow:0.11
-
cpe:2.3:a:jeremy_elson:tcpflow:0.12
-
cpe:2.3:a:jeremy_elson:tcpflow:0.20