CVE-2004-1388: High severity BerliOS Gps Daemon vulnerability
Format string vulnerability in the gpsdreport function for BerliOS GPD daemon (gpsd, formerly pygps) 1.9.0 through 2.7 allows remote attackers to execute arbitrary code via certain GPS requests containing format string specifiers that are not properly handled in syslog calls.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1388?
CVE-2004-1388 has been classified as a critical vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2004-1388?
To fix CVE-2004-1388, update the BerliOS GPD daemon to version 2.8 or later, as earlier versions contain the vulnerability.
What software versions are affected by CVE-2004-1388?
CVE-2004-1388 affects BerliOS GPD daemon versions 1.9.0 through 2.7.
What type of vulnerability is CVE-2004-1388?
CVE-2004-1388 is a format string vulnerability that can be exploited through malformed GPS requests.
Can CVE-2004-1388 be exploited locally?
No, CVE-2004-1388 is a remote vulnerability that requires an attacker to send a specially crafted request to exploit.