Lucene search

K
ubuntucveUbuntu.comUB:CVE-2004-1388
HistoryDec 31, 2004 - 12:00 a.m.

CVE-2004-1388

2004-12-3100:00:00
ubuntu.com
ubuntu.com
15

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.658

Percentile

98.0%

Format string vulnerability in the gpsd_report function for BerliOS GPD
daemon (gpsd, formerly pygps) 1.9.0 through 2.7 allows remote attackers to
execute arbitrary code via certain GPS requests containing format string
specifiers that are not properly handled in syslog calls.

OSVersionArchitecturePackageVersionFilename
ubuntu6.06noarchgpsd< 2.30-1ubuntu3UNKNOWN
ubuntu6.10noarchgpsd< 2.30-1ubuntu3UNKNOWN
ubuntu7.04noarchgpsd< 2.30-1ubuntu3UNKNOWN

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.658

Percentile

98.0%