Back

CVE-2003-0584

Format string vulnerability in Backup and Restore Utility for Unix (BRU) 17.0 and earlier, when running setuid, allows local users to execute arbitrary code via format string specifiers in a command line argument.

Published: Aug 18, 2003 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
tolis_group bru *

GitHub Security Advisory GHSA-crpv-hpv3-mpq2

Format string vulnerability in Backup and Restore Utility for Unix (BRU) 17.0 and earlier, when...

Risk Scores

CVSS Score 7.2 / 10
EPSS Score 1.04%

Top 39% most likely to be exploited

Threat Score 29.1 / 100

Data Sources

NVD EPSS GitHub