CVE-2003-0041: OS Command Injection
Published Feb 1, 2003
·Updated
Kerberos FTP client allows remote FTP sites to execute arbitrary code via a pipe (|) character in a filename that is retrieved by the client.
Affected Software
18 affected components
MIT Kerberos Ftp Client
redhat Linux=6.2
redhat Linux=7.0
redhat Linux=7.1
redhat Linux=7.2
redhat Linux=7.3
redhat Linux=8.0
Mandrakesoft Mandrake Multi Network Firewall=8.2
Mandrakesoft Mandrake Linux=8.1
Mandrakesoft Mandrake Linux=8.2
Mandrakesoft Mandrake Linux=9.0
redhat Linux=7.2
redhat Linux=7.1
redhat Linux=8.0
redhat Linux=7.3
redhat Linux=6.2
redhat Linux=7.0
redhat Linux=7.2
Remediation
Patch Available
Event History
Feb 1, 2003
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Feb 19, 2003
Data Sourced
via NVD·05:00 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2003-0041?
CVE-2003-0041 is considered a high severity vulnerability due to its potential for arbitrary code execution.
2
How do I fix CVE-2003-0041?
To fix CVE-2003-0041, update your Kerberos FTP client or use safer alternatives for FTP connections.
3
Which software is affected by CVE-2003-0041?
CVE-2003-0041 affects several versions of MIT Kerberos FTP client and various versions of Red Hat and Mandrake Linux.
4
Is CVE-2003-0041 still a concern today?
While CVE-2003-0041 was significant at the time, it largely depends on whether outdated software is still in use today.
5
How does CVE-2003-0041 allow arbitrary code execution?
CVE-2003-0041 allows arbitrary code execution through the manipulation of filenames using a pipe (|) character in FTP requests.