CVE-2003-1294: Low severity Xscreensaver Xscreensaver vulnerability
Xscreensaver before 4.15 creates temporary files insecurely in (1) driver/passwd-kerberos.c, (2) driver/xscreensaver-getimage-video, (3) driver/xscreensaver.kss.in, and the (4) vidwhacker and (5) webcollage screensavers, which allows local users to overwrite arbitrary files via a symlink attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2003-1294?
CVE-2003-1294 has a moderate severity level due to the potential for local users to perform symlink attacks.
How do I fix CVE-2003-1294?
To fix CVE-2003-1294, users should upgrade to a patched version of Xscreensaver that addresses the insecure temporary file creation.
Which versions of Xscreensaver are affected by CVE-2003-1294?
CVE-2003-1294 affects Xscreensaver versions prior to 4.15, including several earlier versions such as 4.14_5 and 4.10_15.
What type of attack does CVE-2003-1294 enable?
CVE-2003-1294 enables local users to overwrite arbitrary files through a symlink attack by exploiting temporary files created insecurely.
Is CVE-2003-1294 a remote or local vulnerability?
CVE-2003-1294 is classified as a local vulnerability, as it requires local access to the system to exploit.