Back

CVE-2003-0671

Format string vulnerability in tcpflow, when used in a setuid context, allows local users to execute arbitrary code via the device name argument, as demonstrated in Sustworks IPNetSentryX and IPNetMonitorX the setuid program RunTCPFlow.

Published: Aug 27, 2003 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (4)

Vendor Product Version
jeremy_elson tcpflow 0.10
jeremy_elson tcpflow 0.11
jeremy_elson tcpflow 0.12
jeremy_elson tcpflow 0.20

GitHub Security Advisory GHSA-787m-83jr-r46c

Format string vulnerability in tcpflow, when used in a setuid context, allows local users to...

Risk Scores

CVSS Score 7.2 / 10
EPSS Score 0.55%

Top 57% most likely to be exploited

Threat Score 29 / 100

Data Sources

NVD EPSS GitHub