First published: Tue Jun 10 2003(Updated: )
Buffer overflow in xaos 3.0-23 and earlier, when running setuid, allows local users to gain root privileges via a long -language option.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Debian Linux | =3.0.23 | |
Debian Linux | =3.0.18 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0385 is considered critical as it allows local users to gain root privileges due to a buffer overflow vulnerability.
To fix CVE-2003-0385, upgrade to a fixed version of xaos or remove the setuid bit from the executable.
CVE-2003-0385 affects xaos versions 3.0-23 and earlier, specifically on Debian systems 3.0.23 and 3.0.18.
CVE-2003-0385 can be exploited by local users who have access to execute the xaos program.
CVE-2003-0385 allows a local user to perform a privilege escalation attack, gaining root access on the system.