Back

CVE-2004-0536

Format string vulnerability in Tripwire commercial 4.0.1 and earlier, including 2.4, and open source 2.3.1 and earlier, allows local users to gain privileges via format string specifiers in a file name, which is used in the generation of an email report.

Published: Aug 6, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (11)

Vendor Product Version
tripwire tripwire 2.2.1
tripwire tripwire 2.3.0
tripwire tripwire 2.3.1
tripwire tripwire 2.3.1.2
tripwire tripwire 2.4.0
tripwire tripwire 2.4.2
tripwire tripwire 3.0
tripwire tripwire 3.0.1
tripwire tripwire 4.0
tripwire tripwire 4.0.1
tripwire tripwire 4.1

GitHub Security Advisory GHSA-wwfg-grx5-fq38

Format string vulnerability in Tripwire commercial 4.0.1 and earlier, including 2.4, and open...

Risk Scores

CVSS Score 7.2 / 10
EPSS Score 0.37%

Top 70% most likely to be exploited

Threat Score 28.9 / 100

Data Sources

NVD EPSS GitHub