CVE-2003-0697: High severity IBM AIX vulnerability
Format string vulnerability in lpd in the bos.rte.printers fileset for AIX 4.3 through 5.2, with debug enabled, allows local users to cause a denial of service (crash) or gain root privileges.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable debug mode for lpd in the bos.rte.printers fileset; ensure lpd is not started or configured with debugging enabled, since the vulnerability occurs only when debug is enabled.
bos.rte.printers (lpd) debug = disabled
Event History
Frequently Asked Questions
What is the severity of CVE-2003-0697?
CVE-2003-0697 is considered a critical vulnerability due to its potential to allow local users to gain root privileges.
How do I fix CVE-2003-0697?
To fix CVE-2003-0697, ensure that debug mode is disabled in the lpd configuration and apply any relevant patches provided by IBM.
What systems are affected by CVE-2003-0697?
CVE-2003-0697 affects IBM AIX versions 4.3, 5.1, and 5.2.
What type of attack is possible with CVE-2003-0697?
CVE-2003-0697 allows local users to exploit a format string vulnerability to crash services or escalate privileges.
Is remote exploitation possible with CVE-2003-0697?
CVE-2003-0697 is not remotely exploitable as it requires local access to the affected system.