Vulnerabilities > CVE-2002-0851 - Unspecified vulnerability in Isdn4Linux 3.1Pre1

047910
CVSS 7.2 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
low complexity
isdn4linux
exploit available

Summary

Format string vulnerability in ISDN Point to Point Protocol (PPP) daemon (ipppd) in the ISDN4Linux (i4l) package allows local users to gain root privileges via format strings in the device name command line argument, which is not properly handled in a call to syslog.

Vulnerable Configurations

Part Description Count
Application
Isdn4Linux
1

Exploit-Db

  • descriptionISDN4Linux 3.1 IPPPD Device String SysLog Format String Vulnerability (2). CVE-2002-0851. Local exploit for linux platform
    idEDB-ID:21701
    last seen2016-02-02
    modified2002-08-10
    published2002-08-10
    reporterTESO Security
    sourcehttps://www.exploit-db.com/download/21701/
    titleISDN4Linux 3.1 IPPPD Device String SysLog Format String Vulnerability 2
  • descriptionISDN4Linux 3.1 IPPPD Device String SysLog Format String Vulnerability (1). CVE-2002-0851. Local exploit for linux platform
    idEDB-ID:21700
    last seen2016-02-02
    modified2002-08-10
    published2002-08-10
    reporterGobbles Security
    sourcehttps://www.exploit-db.com/download/21700/
    titleISDN4Linux 3.1 IPPPD Device String SysLog Format String Vulnerability 1