Back
CVE-2003-0671
Format string vulnerability in tcpflow, when used in a setuid context, allows local users to execute arbitrary code via the device name argument, as demonstrated in Sustworks IPNetSentryX and IPNetMonitorX the setuid program RunTCPFlow.
Published: Aug 27, 2003
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (4)
| Vendor | Product | Version |
|---|---|---|
| jeremy_elson | tcpflow | 0.10 |
| jeremy_elson | tcpflow | 0.11 |
| jeremy_elson | tcpflow | 0.12 |
| jeremy_elson | tcpflow | 0.20 |
GitHub Security Advisory GHSA-787m-83jr-r46c
Format string vulnerability in tcpflow, when used in a setuid context, allows local users to...
References (4)
- http://www.atstake.com/research/advisories/2003/a080703-1.txt Exploit, Patch, Vendor Advisory
- http://www.atstake.com/research/advisories/2003/a080703-2.txt
- http://www.atstake.com/research/advisories/2003/a080703-1.txt Exploit, Patch, Vendor Advisory
- http://www.atstake.com/research/advisories/2003/a080703-2.txt
Risk Scores
CVSS Score
7.2 / 10
EPSS Score
0.55%
Top 57% most likely to be exploited
Threat Score
29 / 100
Data Sources
NVD
EPSS
GitHub