Back
CVE-2004-1388
Format string vulnerability in the gpsd_report function for BerliOS GPD daemon (gpsd, formerly pygps) 1.9.0 through 2.7 allows remote attackers to execute arbitrary code via certain GPS requests containing format string specifiers that are not properly handled in syslog calls.
Published: Dec 31, 2004
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (17)
| Vendor | Product | Version |
|---|---|---|
| berlios | gps_daemon | 1.9.0 |
| berlios | gps_daemon | 1.25 |
| berlios | gps_daemon | 1.26 |
| berlios | gps_daemon | 1.91 |
| berlios | gps_daemon | 1.92 |
| berlios | gps_daemon | 1.93 |
| berlios | gps_daemon | 1.94 |
| berlios | gps_daemon | 1.95 |
| berlios | gps_daemon | 1.96 |
| berlios | gps_daemon | 1.97 |
| berlios | gps_daemon | 1.98 |
| berlios | gps_daemon | 2.0 |
| berlios | gps_daemon | 2.1 |
| berlios | gps_daemon | 2.2 |
| berlios | gps_daemon | 2.3 |
| berlios | gps_daemon | 2.4 |
| berlios | gps_daemon | 2.7 |
GitHub Security Advisory GHSA-6g3h-vj3c-7f68
Format string vulnerability in the gpsd_report function for BerliOS GPD daemon (gpsd, formerly...
References (10)
- http://lists.berlios.de/pipermail/gpsd-announce/2005-January/000018.html Patch
- http://marc.info/?l=bugtraq&m=110677341711505&w=2
- http://www.digitalmunition.com/DMA%5B2005-0125a%5D.txt Exploit
- http://www.mail-archive.com/debian-bugs-closed%40lists.debian.org/msg02103.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19079
- http://lists.berlios.de/pipermail/gpsd-announce/2005-January/000018.html Patch
- http://marc.info/?l=bugtraq&m=110677341711505&w=2
- http://www.digitalmunition.com/DMA%5B2005-0125a%5D.txt Exploit
- http://www.mail-archive.com/debian-bugs-closed%40lists.debian.org/msg02103.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19079
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
68.20%
Top 1% most likely to be exploited
Threat Score
50.5 / 100
Data Sources
NVD
EPSS
GitHub