Vulnerabilities > CVE-2002-0525 - Local Format String Vulnerabilties in ISC INN

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
isc
critical
exploit available

Summary

Format string vulnerabilities in (1) inews or (2) rnews for INN 2.2.3 and earlier allow local users and remote malicious NNTP servers to gain privileges via format string specifiers in NTTP responses.

Vulnerable Configurations

Part Description Count
Application
Isc
6

Exploit-Db

descriptionISC INN 2.0/2.1/2.2.x Multiple Local Format String Vulnerabilties. CVE-2002-0525. Local exploit for linux platform
idEDB-ID:21375
last seen2016-02-02
modified2002-04-11
published2002-04-11
reporterPaul Starzetz
sourcehttps://www.exploit-db.com/download/21375/
titleISC INN 2.0/2.1/2.2.x - Multiple Local Format String Vulnerabilties