CVE-2003-1236 EXPLOIT
10.0
HIGH · CVSS 2.0 · EPSS 15.2% (pctl 97)
Patch early
A public exploit exists.
Description
Multiple format string vulnerabilities in the logger function in netzio.c for Tanne 0.6.17 allows remote attackers to execute arbitrary code via format string specifiers in syslog.
Scoring
| CVSS | 10.0 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| EPSS | 15.19% — more likely to be exploited than 97% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2003-12-31 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| tanne | tanne |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | TANne 0.6.17 - Session Manager SysLog Format String | 2003-01-07 |
References
- http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0011.html
- http://secunia.com/advisories/7831
- http://tanne.fluxnetz.de/download/tanne-0.7.1.tar.bz2
- http://www.iss.net/security_center/static/11006.php
- http://www.securityfocus.com/archive/1/305460
- http://www.securityfocus.com/archive/1/305663
- http://www.securityfocus.com/bid/6553
- http://www.securitytracker.com/id?1005900
- http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0011.html
- http://secunia.com/advisories/7831
- http://tanne.fluxnetz.de/download/tanne-0.7.1.tar.bz2
- http://www.iss.net/security_center/static/11006.php
- http://www.securityfocus.com/archive/1/305460
- http://www.securityfocus.com/archive/1/305663
- http://www.securityfocus.com/bid/6553
- http://www.securitytracker.com/id?1005900
→ the Explorer · watch your stack · NVD