CVE-2003-0840: Buffer Overflow
Published Oct 9, 2003
·Updated
Buffer overflow in dtprintinfo on HP-UX 11.00, and possibly other operating systems, allows local users to gain root privileges via a long DISPLAY environment variable.
Affected Software
1 affected component
HPE HP-UX=11.00
Event History
Oct 9, 2003
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Nov 17, 2003
Data Sourced
via NVD·05:00 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2003-0840?
The severity of CVE-2003-0840 is considered high due to the potential for local users to gain root privileges.
2
How does CVE-2003-0840 exploit the system?
CVE-2003-0840 exploits the system through a buffer overflow caused by a long DISPLAY environment variable.
3
Who is affected by CVE-2003-0840?
CVE-2003-0840 affects local users of HP-UX 11.00 and potentially other operating systems.
4
How do I fix CVE-2003-0840?
To fix CVE-2003-0840, it is recommended to limit the length of the DISPLAY environment variable and apply any available patches from HP.
5
Is there a workaround for CVE-2003-0840?
A potential workaround for CVE-2003-0840 is to use a restricted user account that does not have access to set the DISPLAY variable.