CVE-2002-0412
Summary
| CVE | CVE-2002-0412 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2002-08-12 04:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Format string vulnerability in TraceEvent function for ntop before 2.1 allows remote attackers to execute arbitrary code by causing format strings to be injected into calls to the syslog function, via (1) an HTTP GET request, (2) a user name in HTTP authentication, or (3) a password in HTTP authentication. |
Risk And Classification
Primary CVSS: v2.0 7.5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| ntop Remote Format String Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch, Vendor Advisory |
| Neohapsis Archives - VulnWatch - [VulnWatch] [H20020304]: Remotely exploitable format string vulnerability in ntop - From [email protected] | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | |
| SecurityFocus HOME Mailing List: BugTraq | af854a3a-2127-422b-91ae-364da2661108 | online.securityfocus.com | Vendor Advisory |
| ISS X-Force Database: ntop-traceevent-format-string (8347): Ntop traceEvent() function format string | af854a3a-2127-422b-91ae-364da2661108 | www.iss.net | Patch, Vendor Advisory |
| www.osvdb.org/5307 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| 'ALERT ALERT ALERT ALERT ALERT ALERT ALERT ALERT ALERT ALERT ALERT' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| [Ntop-dev] ntop - format string bug in traceEvent | af854a3a-2127-422b-91ae-364da2661108 | listmanager.unipi.it | |
| The NTOP community page | af854a3a-2127-422b-91ae-364da2661108 | snapshot.ntop.org | |
| 're: gobbles ntop alert' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| 'segfault in ntop' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.