CVE-2003-0885: Medium severity Xscreensaver Xscreensaver vulnerability
Xscreensaver 4.14 contains certain debugging code that should have been omitted, which causes Xscreensaver to create temporary files insecurely in the (1) apple2, (2) xanalogtv, and (3) pong screensavers, and allows local users to overwrite arbitrary files via a symlink attack.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2003-0885?
CVE-2003-0885 is classified as a moderate severity vulnerability due to its potential for local user exploitation.
How do I fix CVE-2003-0885?
To fix CVE-2003-0885, upgrade to a newer version of Xscreensaver that does not include the insecure temporary file creation.
Who is affected by CVE-2003-0885?
Local users on systems running Xscreensaver version 4.14 are affected by CVE-2003-0885.
What attacks can be performed using CVE-2003-0885?
CVE-2003-0885 allows local users to perform symlink attacks to overwrite arbitrary files.
What software versions are impacted by CVE-2003-0885?
CVE-2003-0885 specifically impacts Xscreensaver version 4.14.