Описание
Format string vulnerability in ISDN Point to Point Protocol (PPP) daemon (ipppd) in the ISDN4Linux (i4l) package allows local users to gain root privileges via format strings in the device name command line argument, which is not properly handled in a call to syslog.
Ссылки
- ExploitVendor Advisory
- PatchVendor Advisory
- ExploitPatchVendor Advisory
- ExploitVendor Advisory
- PatchVendor Advisory
- ExploitPatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:isdn4linux:isdn4linux:3.1_pre1:*:*:*:*:*:*:*
EPSS
Процентиль: 70%
0.00639
Низкий
7.2 High
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
debian
почти 23 года назад
Format string vulnerability in ISDN Point to Point Protocol (PPP) daem ...
github
больше 3 лет назад
Format string vulnerability in ISDN Point to Point Protocol (PPP) daemon (ipppd) in the ISDN4Linux (i4l) package allows local users to gain root privileges via format strings in the device name command line argument, which is not properly handled in a call to syslog.
EPSS
Процентиль: 70%
0.00639
Низкий
7.2 High
CVSS2
Дефекты
NVD-CWE-Other