CVE-2004-1484
EPSS 7.3%
描述
Format string vulnerability in the _msg function in error.c in socat 1.4.0.3 and earlier, when used as an HTTP proxy client and run with the -ly option, allows remote attackers or local users to execute arbitrary code via format string specifiers in a syslog message.
如何修補 CVE-2004-1484
要修補 CVE-2004-1484,請將受影響套件升級到下列已修補版本。
- Debian/socat—升級至 1.4.0.3-1 或更新版本
CVE-2004-1484 正在被利用嗎?
中等 — EPSS 為 7.3%,可持續追蹤但非最高優先。
受影響套件(1)
- from 0, < 1.4.0.3-1