Back

CVE-2004-1469

Format string vulnerability in the log function in SUS 2.0.2, and other versions before 2.0.6, allows local users to execute arbitrary code via format string specifiers in a command line argument that is passed directly to syslog.

Published: Dec 31, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (2)

Vendor Product Version
peter_d._gray sus 2.0
peter_d._gray sus 2.0.1

GitHub Security Advisory GHSA-mch4-wjp2-wj65

Format string vulnerability in the log function in SUS 2.0.2, and other versions before 2.0.6,...

Risk Scores

CVSS Score 7.2 / 10
EPSS Score 0.62%

Top 53% most likely to be exploited

Threat Score 29 / 100

Data Sources

NVD EPSS GitHub