CVE-2004-2026

Format string vulnerability in the logmsg function in svc.c for Pound 1.5 and earlier allows remote attackers to execute arbitrary code via format string specifiers in syslog messages.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apsis:pound:1.0:*:*:*:*:*:*:*
cpe:2.3:a:apsis:pound:1.1:*:*:*:*:*:*:*
cpe:2.3:a:apsis:pound:1.2:*:*:*:*:*:*:*
cpe:2.3:a:apsis:pound:1.3:*:*:*:*:*:*:*
cpe:2.3:a:apsis:pound:1.4:*:*:*:*:*:*:*
cpe:2.3:a:apsis:pound:1.5:*:*:*:*:*:*:*

History

20 Nov 2024, 23:52

Type Values Removed Values Added
References () http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0343.html - Exploit () http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0343.html - Exploit
References () http://secunia.com/advisories/11528 - Patch () http://secunia.com/advisories/11528 - Patch
References () http://security.gentoo.org/glsa/glsa-200405-08.xml - Patch () http://security.gentoo.org/glsa/glsa-200405-08.xml - Patch
References () http://securitytracker.com/id?1010034 - () http://securitytracker.com/id?1010034 -
References () http://www.apsis.ch/pound/pound_list/archive/2003/2003-12/1070234315000#1070234315000 - () http://www.apsis.ch/pound/pound_list/archive/2003/2003-12/1070234315000#1070234315000 -
References () http://www.osvdb.org/5746 - () http://www.osvdb.org/5746 -
References () http://www.securityfocus.com/bid/10267 - Exploit, Patch () http://www.securityfocus.com/bid/10267 - Exploit, Patch
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/16033 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/16033 -

Information

Published : 2004-12-31 05:00

Updated : 2024-11-20 23:52


NVD link : CVE-2004-2026

Mitre link : CVE-2004-2026

CVE.ORG link : CVE-2004-2026


JSON object : View

Products Affected

apsis

  • pound