Back
CVE-2002-0913
Format string vulnerability in log_doit function of Slurp NNTP client 1.1.0 allows a malicious news server to execute arbitrary code on the client via format strings in a server response.
Published: Oct 4, 2002
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| stephen_hebditch | slurp | 1.1.0 |
GitHub Security Advisory GHSA-qf95-mrh8-8c54
Format string vulnerability in log_doit function of Slurp NNTP client 1.1.0 allows a malicious...
References (8)
- http://archives.neohapsis.com/archives/bugtraq/2002-06/0014.html
- http://marc.info/?l=vuln-dev&m=102323341407280&w=2
- http://www.iss.net/security_center/static/9270.php Vendor Advisory
- http://www.securityfocus.com/bid/4935 Exploit, Patch, Vendor Advisory
- http://archives.neohapsis.com/archives/bugtraq/2002-06/0014.html
- http://marc.info/?l=vuln-dev&m=102323341407280&w=2
- http://www.iss.net/security_center/static/9270.php Vendor Advisory
- http://www.securityfocus.com/bid/4935 Exploit, Patch, Vendor Advisory
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
4.51%
Top 9% most likely to be exploited
Threat Score
31.4 / 100
Data Sources
NVD
EPSS
GitHub