CVE-2004-0393
rlpr - several vulnerabilities
EPSS 17.4%
Description
Format string vulnerability in the msg function for rlpr daemon (rlprd) 2.0.4 allows remote attackers to execute arbitrary code via format string specifiers in a buffer that can not be resolved, which is provided to the syslog function.
How to fix CVE-2004-0393
To remediate CVE-2004-0393, upgrade the affected package to a fixed version below.
- Debian/rlpr—upgrade to 2.02-7.1 or later
- Debian/rlpr—upgrade to 2.02-7woody1 or later
Is CVE-2004-0393 being exploited?
Moderate — EPSS is 17.4%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (2)
- from 0, < 2.02-7.1
- from 0, < 2.02-7woody1