CVE-2003-0671

Format string vulnerability in tcpflow, when used in a setuid context, allows local users to execute arbitrary code via the device name argument, as demonstrated in Sustworks IPNetSentryX and IPNetMonitorX the setuid program RunTCPFlow.

Scoring

CVSS base score
0
EPSS probability
0.06%
Published
2003-08-14
Last modified
2026-03-16

Affected products

Markdown version · Browse all CVEs