First published: Wed Dec 31 2003(Updated: )
Xscreensaver 4.14 contains certain debugging code that should have been omitted, which causes Xscreensaver to create temporary files insecurely in the (1) apple2, (2) xanalogtv, and (3) pong screensavers, and allows local users to overwrite arbitrary files via a symlink attack.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
XScreenSaver | =4.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0885 is classified as a moderate severity vulnerability due to its potential for local user exploitation.
To fix CVE-2003-0885, upgrade to a newer version of Xscreensaver that does not include the insecure temporary file creation.
Local users on systems running Xscreensaver version 4.14 are affected by CVE-2003-0885.
CVE-2003-0885 allows local users to perform symlink attacks to overwrite arbitrary files.
CVE-2003-0885 specifically impacts Xscreensaver version 4.14.