Back
CVE-2004-2386
Format string vulnerability in the LogMsg function in sercd before 2.3.1 and sredird 2.2.1 and earlier allows remote attackers to execute arbitrary code via format string specifiers passed from the HandleCPCCommand function.
Published: Dec 31, 2004
Modified: Jun 16, 2026
CWE-134
CVSS Metrics
Affected Products (9)
| Vendor | Product | Version |
|---|---|---|
| denis_sbragion | sredird | 1.0 |
| denis_sbragion | sredird | 1.1.6 |
| denis_sbragion | sredird | 1.1.7 |
| denis_sbragion | sredird | 1.1.8 |
| denis_sbragion | sredird | 2.0 |
| denis_sbragion | sredird | 2.1 |
| denis_sbragion | sredird | 2.2 |
| denis_sbragion | sredird | 2.2.1 |
| peter_astrand | sercd | 2.3.0 |
GitHub Security Advisory GHSA-9hxf-7mx9-m3j2
Format string vulnerability in the LogMsg function in sercd before 2.3.1 and sredird 2.2.1 and...
References (16)
- http://cvs.lysator.liu.se/viewcvs/viewcvs.cgi/sercd/sercd.c?root=sercd
- http://secunia.com/advisories/12351 Vendor Advisory
- http://securitytracker.com/id?1011038
- http://www.osvdb.org/8375 Patch
- http://www.osvdb.org/9104
- http://www.securityfocus.com/bid/11002
- http://www.securityfocus.com/bid/11031 Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17056
- http://cvs.lysator.liu.se/viewcvs/viewcvs.cgi/sercd/sercd.c?root=sercd
- http://secunia.com/advisories/12351 Vendor Advisory
- http://securitytracker.com/id?1011038
- http://www.osvdb.org/8375 Patch
- http://www.osvdb.org/9104
- http://www.securityfocus.com/bid/11002
- http://www.securityfocus.com/bid/11031 Patch
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
3.21%
Top 13% most likely to be exploited
Threat Score
31 / 100
Data Sources
NVD
EPSS
GitHub