Lucene search

K
cveMitreCVE-2004-0172
HistoryMar 15, 2004 - 5:00 a.m.

CVE-2004-0172

2004-03-1505:00:00
mitre
web.nvd.nist.gov
22
cve
ltrace
buffer overflow
security
code execution
nvd

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.6

Confidence

High

EPSS

0

Percentile

5.1%

Heap-based buffer overflow in the search_for_command function of ltrace 0.3.10, if it is installed setuid, could allow local users to execute arbitrary code via a long filename. NOTE: It is unclear whether there are any packages that install ltrace as a setuid program, so this candidate might be REJECTed.

Affected configurations

Nvd
Node
juan_cespedesltraceMatch0.3.10
VendorProductVersionCPE
juan_cespedesltrace0.3.10cpe:2.3:a:juan_cespedes:ltrace:0.3.10:*:*:*:*:*:*:*

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.6

Confidence

High

EPSS

0

Percentile

5.1%

Related for CVE-2004-0172