CVE-2003-0547: Low severity gnome gdm vulnerability
Published Aug 22, 2003
·Updated
GDM before 2.4.1.6, when using the "examine session errors" feature, allows local users to read arbitrary files via a symlink attack on the ~/.xsession-errors file.
Affected Software
9 affected components
Gnome gdm=2.4.1
Gnome gdm=2.4.1.1
Gnome gdm=2.4.1.2
Gnome gdm=2.4.1.3
Gnome gdm=2.4.1.4
Gnome gdm=2.4.1.5
Gnome gdm=2.4.1.6
redhat Kdebase=2.4.0.7.13
redhat Kdebase=2.4.1.3.5
Remediation
Patch Available
Event History
Aug 22, 2003
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Aug 27, 2003
Data Sourced
via NVD·04:00 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2003-0547?
CVE-2003-0547 is classified as a moderate severity vulnerability due to its potential for local file access exploitation.
2
How do I fix CVE-2003-0547?
To fix CVE-2003-0547, upgrade GDM to version 2.4.1.7 or later.
3
What impact does CVE-2003-0547 have on affected systems?
CVE-2003-0547 allows local users to read arbitrary files, potentially compromising sensitive information.
4
Which versions of GDM are affected by CVE-2003-0547?
Versions GDM 2.4.1 to 2.4.1.6 are affected by CVE-2003-0547.
5
Who is at risk from CVE-2003-0547?
Local users on systems running vulnerable versions of GDM are at risk from CVE-2003-0547.