Back
CVE-2004-0536
Format string vulnerability in Tripwire commercial 4.0.1 and earlier, including 2.4, and open source 2.3.1 and earlier, allows local users to gain privileges via format string specifiers in a file name, which is used in the generation of an email report.
Published: Aug 6, 2004
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (11)
| Vendor | Product | Version |
|---|---|---|
| tripwire | tripwire | 2.2.1 |
| tripwire | tripwire | 2.3.0 |
| tripwire | tripwire | 2.3.1 |
| tripwire | tripwire | 2.3.1.2 |
| tripwire | tripwire | 2.4.0 |
| tripwire | tripwire | 2.4.2 |
| tripwire | tripwire | 3.0 |
| tripwire | tripwire | 3.0.1 |
| tripwire | tripwire | 4.0 |
| tripwire | tripwire | 4.0.1 |
| tripwire | tripwire | 4.1 |
GitHub Security Advisory GHSA-wwfg-grx5-fq38
Format string vulnerability in Tripwire commercial 4.0.1 and earlier, including 2.4, and open...
References (12)
- http://marc.info/?l=bugtraq&m=108627481507249&w=2
- http://marc.info/?l=bugtraq&m=108630983009228&w=2
- http://security.gentoo.org/glsa/glsa-200406-02.xml Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2004-244.html
- http://www.securityfocus.com/bid/10454
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16309
- http://marc.info/?l=bugtraq&m=108627481507249&w=2
- http://marc.info/?l=bugtraq&m=108630983009228&w=2
- http://security.gentoo.org/glsa/glsa-200406-02.xml Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2004-244.html
- http://www.securityfocus.com/bid/10454
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16309
Risk Scores
CVSS Score
7.2 / 10
EPSS Score
0.37%
Top 70% most likely to be exploited
Threat Score
28.9 / 100
Data Sources
NVD
EPSS
GitHub