Unrated severityNVD Advisory· Published Dec 31, 2004· Updated Apr 16, 2026
CVE-2004-1469
CVE-2004-1469
Description
Format string vulnerability in the log function in SUS 2.0.2, and other versions before 2.0.6, allows local users to execute arbitrary code via format string specifiers in a command line argument that is passed directly to syslog.
Affected products
2cpe:2.3:a:peter_d._gray:sus:2.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:peter_d._gray:sus:2.0:*:*:*:*:*:*:*
- cpe:2.3:a:peter_d._gray:sus:2.0.1:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- www.gentoo.org/security/en/glsa/glsa-200409-17.xmlnvdPatch
- security.lss.hr/index.phpnvdExploitPatchVendor Advisory
- www.securityfocus.com/bid/11176nvdExploitPatch
- marc.infonvd
- pdg.uow.edu.au/sus/CHANGESnvd
- exchange.xforce.ibmcloud.com/vulnerabilities/17361nvd
News mentions
0No linked articles in our index yet.