The rpc.statd program passes user-supplied data to the syslog() function as a format string. If there is no input validation of this string, a malicious user can inject machine code to be executed with the privileges of the rpc.statd process, typically root. This is a ONE SHOT exploit. This exploit is able to attack a Redhat and a Suse system in a 'one shot' attack.
CVE Link
Exploit Platform
Product Name