CVE-2004-2386
Summary
| CVE | CVE-2004-2386 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2004-12-31 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Format string vulnerability in the LogMsg function in sercd before 2.3.1 and sredird 2.2.1 and earlier allows remote attackers to execute arbitrary code via format string specifiers passed from the HandleCPCCommand function. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Denis Sbragion | Sredird | 1.0 | All | All | All |
| Application | Denis Sbragion | Sredird | 1.1.6 | All | All | All |
| Application | Denis Sbragion | Sredird | 1.1.7 | All | All | All |
| Application | Denis Sbragion | Sredird | 1.1.8 | All | All | All |
| Application | Denis Sbragion | Sredird | 2.0 | All | All | All |
| Application | Denis Sbragion | Sredird | 2.1 | All | All | All |
| Application | Denis Sbragion | Sredird | 2.2 | All | All | All |
| Application | Denis Sbragion | Sredird | 2.2.1 | All | All | All |
| Application | Peter Astrand | Sercd | 2.3.0 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Sredird Multiple Remote Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Secunia - Advisories - sredird Client Signature Information Processing Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| www.osvdb.org/9104 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| www.securityfocus.com/bid/11031 | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch |
| www.osvdb.org/8375 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | Patch |
| SecurityTracker.com Archives - sredird LogMsg() Format String Bug and HandleCPCCommand() Buffer Overflow May Let Remote Users Execute Arbitrary Code | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| CVS Repository @ Lysator ACS - log - sercd: sercd/sercd.c | af854a3a-2127-422b-91ae-364da2661108 | cvs.lysator.liu.se | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.