CVE

Id
7498  
CVE No.
CVE-2003-0671  
Status
Candidate  
Description
Format string vulnerability in tcpflow, when used in a setuid context, allows local users to execute arbitrary code via the device name argument, as demonstrated in Sustworks IPNetSentryX and IPNetMonitorX the setuid program RunTCPFlow.  
Phase
Assigned (20030807)  
Votes
None (candidate not yet proposed)  
Comments