First published: Wed Jan 26 2005(Updated: )
The scosession program in OpenServer 5.0.6 and 5.0.7 allows local users to gain privileges via crafted strings on the commandline.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Xinuos OpenServer | =5.0 | |
Xinuos OpenServer | =5.0.1 | |
Xinuos OpenServer | =5.0.2 | |
Xinuos OpenServer | =5.0.3 | |
Xinuos OpenServer | =5.0.4 | |
Xinuos OpenServer | =5.0.5 | |
Xinuos OpenServer | =5.0.6 | |
Xinuos OpenServer | =5.0.6a | |
Xinuos OpenServer | =5.0.7 | |
Xinuos OpenServer | =5.0 | |
Xinuos OpenServer | =5.0.2 | |
Xinuos OpenServer | =5.0.7 | |
Xinuos OpenServer | =5.0.5 | |
Xinuos OpenServer | =5.0.3 | |
Xinuos OpenServer | =5.0.6a | |
Xinuos OpenServer | =5.0.1 | |
Xinuos OpenServer | =5.0.6 | |
Xinuos OpenServer | =5.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-1021 is classified as a high severity vulnerability due to its potential for privilege escalation.
To mitigate CVE-2003-1021, upgrade OpenServer to a version that is not affected, such as any version later than 5.0.7.
Local users of Xinuos OpenServer versions 5.0.6 and 5.0.7 are affected by CVE-2003-1021.
CVE-2003-1021 is caused by the scosession program allowing local users to gain elevated privileges through crafted command line strings.
Yes, there are exploited cases reported that demonstrate how an attacker can utilize this vulnerability to escalate privileges.