VulnerabilityModified
CVE-2001-0717
Format string vulnerability in ToolTalk database server rpc.ttdbserverd allows remote attackers to execute arbitrary commands via format string specifiers that are passed to the syslog function.
HIGH 10.0EPSS 5.71%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.71%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Format string vulnerability in ToolTalk database server rpc.ttdbserverd allows remote attackers to execute arbitrary commands via format string specifiers that are passed to the syslog function.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 5.71% probability · 93th percentile
- CISA KEV
- Not listed
- Affected
- tooltalk/tooltalk database server
- Source
- cve@mitre.org
References
- ftp://stage.caldera.com/pub/security/openunix/CSSA-2001-SCO.28/CSSA-2001-SCO.28.txt
- http://ftp.support.compaq.com/patches/.new/html/SSRT0767U.shtml
- http://online.securityfocus.com/advisories/3584
- http://securitytracker.com/id?1002479
- http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/212
- http://www.cert.org/advisories/CA-2001-27.htmlUS Government Resource
- http://www.ciac.org/ciac/bulletins/m-002.shtml
- http://www.securityfocus.com/bid/3382
- http://xforce.iss.net/alerts/advise98.phpPatch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7069
- ftp://stage.caldera.com/pub/security/openunix/CSSA-2001-SCO.28/CSSA-2001-SCO.28.txt
- http://ftp.support.compaq.com/patches/.new/html/SSRT0767U.shtml
- http://online.securityfocus.com/advisories/3584
- http://securitytracker.com/id?1002479
- http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/212
- http://www.cert.org/advisories/CA-2001-27.htmlUS Government Resource
- http://www.ciac.org/ciac/bulletins/m-002.shtml
- http://www.securityfocus.com/bid/3382
- http://xforce.iss.net/alerts/advise98.phpPatch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7069
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.