CVE-2004-0354: Critical severity GNU Anubis vulnerability
Multiple format string vulnerabilities in GNU Anubis 3.6.0 through 3.6.2, 3.9.92 and 3.9.93 allow remote attackers to execute arbitrary code via format string specifiers in strings passed to (1) the info function in log.c, (2) the anubiserror function in errs.c, or (3) the sslerror function in ssl.c.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0354?
CVE-2004-0354 is classified as a critical vulnerability due to the potential for remote attackers to execute arbitrary code.
Which versions of GNU Anubis are affected by CVE-2004-0354?
CVE-2004-0354 affects GNU Anubis versions 3.6.0 through 3.6.2, as well as 3.9.92 and 3.9.93.
How do I fix CVE-2004-0354?
To fix CVE-2004-0354, upgrade GNU Anubis to a version that is not vulnerable, such as any release after 3.9.93.
What types of vulnerabilities does CVE-2004-0354 include?
CVE-2004-0354 includes multiple format string vulnerabilities in various functions of GNU Anubis.
Can CVE-2004-0354 be exploited remotely?
Yes, CVE-2004-0354 can be exploited remotely via specially crafted format string specifiers.