CVE-2003-0333: Buffer Overflow
Multiple buffer overflows in kermit in HP-UX 10.20 and 11.00 (C-Kermit 6.0.192 and possibly other versions before 8.0) allow local users to gain privileges via long arguments to (1) ask, (2) askq, (3) define, (4) assign, and (5) getc, some of which may share the same underlying function "doask," a different vulnerability than CVE-2001-0085.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
C-Kermitto a version that resolves this vulnerability.Fixed in 8.0
Event History
Frequently Asked Questions
What is the severity of CVE-2003-0333?
CVE-2003-0333 is considered to have a high severity due to its potential to allow local users to gain elevated privileges.
How do I fix CVE-2003-0333?
To fix CVE-2003-0333, users should upgrade to a version of C-Kermit that is 8.0 or later, which addresses these buffer overflow vulnerabilities.
Who is affected by CVE-2003-0333?
CVE-2003-0333 affects local users of HP-UX versions 10.20 and 11.00 running C-Kermit versions 6.0.192 and possibly older.
What type of vulnerability is CVE-2003-0333?
CVE-2003-0333 is a buffer overflow vulnerability that can be exploited via long arguments in specific Kermit commands.
Can CVE-2003-0333 be exploited remotely?
No, CVE-2003-0333 requires local access to the system to exploit the vulnerability.