Multiple format string vulnerabilities in GNU Anubis 3.6.0 through 3.6.2, 3.9.92 and 3.9.93 allow remote attackers to execute arbitrary code via format string specifiers in strings passed to (1) the info function in log.c, (2) the anubis_error function in errs.c, or (3) the ssl_error function in ssl.c.
References
Configurations
Configuration 1 (hide)
|
History
20 Nov 2024, 23:48
Type | Values Removed | Values Added |
---|---|---|
References | () http://mail.gnu.org/archive/html/bug-anubis/2004-02/msg00000.html - | |
References | () http://marc.info/?l=bugtraq&m=107843915424588&w=2 - | |
References | () http://www.securityfocus.com/bid/9772 - Exploit, Patch, Vendor Advisory | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/15346 - |
Information
Published : 2004-11-23 05:00
Updated : 2025-04-03 01:03
NVD link : CVE-2004-0354
Mitre link : CVE-2004-0354
CVE.ORG link : CVE-2004-0354
JSON object : View
Products Affected
gnu
- anubis
CWE