CVE-2003-0385: Buffer Overflow
Published Jun 10, 2003
·Updated
Buffer overflow in xaos 3.0-23 and earlier, when running setuid, allows local users to gain root privileges via a long -language option.
Affected Software
2 affected components
Debian Debian Linux=3.0.23
Debian Debian Linux=3.0.18
Remediation
Patch Available
Event History
Jun 10, 2003
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Jul 2, 2003
Data Sourced
via NVD·04:00 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2003-0385?
CVE-2003-0385 is considered critical as it allows local users to gain root privileges due to a buffer overflow vulnerability.
2
How do I fix CVE-2003-0385?
To fix CVE-2003-0385, upgrade to a fixed version of xaos or remove the setuid bit from the executable.
3
Which software versions are affected by CVE-2003-0385?
CVE-2003-0385 affects xaos versions 3.0-23 and earlier, specifically on Debian systems 3.0.23 and 3.0.18.
4
Who can exploit CVE-2003-0385?
CVE-2003-0385 can be exploited by local users who have access to execute the xaos program.
5
What kind of attack does CVE-2003-0385 allow?
CVE-2003-0385 allows a local user to perform a privilege escalation attack, gaining root access on the system.