CVE-2003-1236

Tanne 0.6.17 - Remote Code Execution via Format String in Logger Function

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2003-1236. PoCs published by dong-h0un yoU.

AI-analyzed exploit summary This exploit targets a format string vulnerability in TANne 0.6.17, leveraging insecure syslog() calls to achieve remote code execution. It crafts a malicious payload to overwrite the GOT entry of syslog() and redirect execution to a shellcode that spawns a rootshell on port 36864.

Description

Multiple format string vulnerabilities in the logger function in netzio.c for Tanne 0.6.17 allows remote attackers to execute arbitrary code via format string specifiers in syslog.

Exploits (1)

exploitdb WORKING POC VERIFIED
by dong-h0un yoU · cremotelinux
https://www.exploit-db.com/exploits/22135

This exploit targets a format string vulnerability in TANne 0.6.17, leveraging insecure syslog() calls to achieve remote code execution. It crafts a malicious payload to overwrite the GOT entry of syslog() and redirect execution to a shellcode that spawns a rootshell on port 36864.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: TANne 0.6.17
No auth needed
Prerequisites: Network access to the vulnerable TANne service · Knowledge of the target system's memory layout (e.g., GOT addresses)
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Exploit, Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/6553
Third Party Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/11006.php
Exploit, Patch mailing-list x_refsource_vulnwatch
http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0011.html
Exploit mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/305663
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1005900
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/7831
Exploit, Patch mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/305460

Scores

EPSS 0.1519
EPSS Percentile 96.3%

Details

Status published
Products (1)
tanne/tanne 0.6.17
Published Dec 31, 2003
Tracked Since Feb 18, 2026