CVE-2003-0584

BRU <17.0 - RCE

Title source: llm
STIX 2.1

Description

Format string vulnerability in Backup and Restore Utility for Unix (BRU) 17.0 and earlier, when running setuid, allows local users to execute arbitrary code via format string specifiers in a command line argument.

Exploits (2)

exploitdb WORKING POC VERIFIED
by nic · clocalunix
https://www.exploit-db.com/exploits/22924
exploitdb WORKING POC VERIFIED
by DVDMAN · clocalunix
https://www.exploit-db.com/exploits/22923

Scores

EPSS 0.0046
EPSS Percentile 63.9%

Details

Status published
Products (1)
tolis_group/bru < 17.0
Published Aug 18, 2003
Tracked Since Feb 18, 2026