Vulnerability Description
Format string vulnerability in the lprintf function in Citadel/UX 6.27 and earlier allows remote attackers to execute arbitrary code via format string specifiers sent to the server.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Citadel | Ux | 6.07 |
References
- http://marc.info/?l=bugtraq&m=110295469430696&w=2
- http://marc.info/?l=bugtraq&m=110304986223400&w=2
- http://www.nosystem.com.ar/advisories/advisory-09.txt
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18429
- http://marc.info/?l=bugtraq&m=110295469430696&w=2
- http://marc.info/?l=bugtraq&m=110304986223400&w=2
- http://www.nosystem.com.ar/advisories/advisory-09.txt
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18429
FAQ
What is CVE-2004-1192?
CVE-2004-1192 is a vulnerability with a CVSS score of 10.0 (HIGH). Format string vulnerability in the lprintf function in Citadel/UX 6.27 and earlier allows remote attackers to execute arbitrary code via format string specifiers sent to the server.
How severe is CVE-2004-1192?
CVE-2004-1192 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2004-1192?
Check the references section above for vendor advisories and patch information. Affected products include: Citadel Ux.