Lucene search

K
cve[email protected]CVE-2004-1484
HistoryFeb 13, 2005 - 5:00 a.m.

CVE-2004-1484

2005-02-1305:00:00
web.nvd.nist.gov
26
socat
http proxy
format string vulnerability
remote code execution
cve-2004-1484

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

7.3 High

AI Score

Confidence

Low

0.025 Low

EPSS

Percentile

90.2%

Format string vulnerability in the _msg function in error.c in socat 1.4.0.3 and earlier, when used as an HTTP proxy client and run with the -ly option, allows remote attackers or local users to execute arbitrary code via format string specifiers in a syslog message.

Affected configurations

NVD
Node
socatsocatMatch1.0.3.0
OR
socatsocatMatch1.0.4.0
OR
socatsocatMatch1.0.4.1
OR
socatsocatMatch1.0.4.2
OR
socatsocatMatch1.1.0.0
OR
socatsocatMatch1.1.0.1
OR
socatsocatMatch1.2.0.0
OR
socatsocatMatch1.3.0.0
OR
socatsocatMatch1.3.0.1
OR
socatsocatMatch1.3.1.0
OR
socatsocatMatch1.3.2.0
OR
socatsocatMatch1.3.2.1
OR
socatsocatMatch1.3.2.2
OR
socatsocatMatch1.4.0.0
OR
socatsocatMatch1.4.0.1
OR
socatsocatMatch1.4.0.2

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

7.3 High

AI Score

Confidence

Low

0.025 Low

EPSS

Percentile

90.2%