CVE-2003-0854: Low severity GNU fileutils vulnerability
ls in the fileutils or coreutils packages allows local users to consume a large amount of memory via a large -w value, which can be remotely exploited via applications that use ls, such as wu-ftpd.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2003-0854?
CVE-2003-0854 is classified as a high severity vulnerability due to its ability to be exploited remotely and consume significant system memory.
How do I fix CVE-2003-0854?
To mitigate CVE-2003-0854, upgrading to the latest version of GNU Fileutils or wu-ftpd that is not affected by this vulnerability is recommended.
Which software versions are affected by CVE-2003-0854?
CVE-2003-0854 affects GNU Fileutils versions 4.0 through 4.1.7 and wu-ftpd versions 2.4.1 through 2.6.2.
Can CVE-2003-0854 be exploited locally?
Yes, CVE-2003-0854 can be exploited locally by users through applications that invoke the 'ls' command.
Are there any workarounds for CVE-2003-0854?
While upgrading is the most effective fix for CVE-2003-0854, limiting access to vulnerable applications and restricting user permissions can serve as temporary workarounds.