CVE-2003-1422: Critical severity Gentoo Syslinux vulnerability
Multiple unspecified vulnerabilities in the installer for SYSLINUX 2.01, when running setuid root, allow local users to gain privileges via unknown vectors.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Remove the setuid root permission from the SYSLINUX 2.01 installer binary (for example, as root run: chmod u-s /path/to/syslinux-installer) so it does not run setuid.
SYSLINUX 2.01 installer setuid bit = disabled
Event History
Frequently Asked Questions
What is the severity of CVE-2003-1422?
CVE-2003-1422 is considered a high severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2003-1422?
To fix CVE-2003-1422, upgrade the SYSLINUX package to a version that is not affected by this vulnerability.
Who is affected by CVE-2003-1422?
Local users with access to systems running SYSLINUX 2.01 setuid root are affected by CVE-2003-1422.
What type of vulnerability is CVE-2003-1422?
CVE-2003-1422 is a local privilege escalation vulnerability.
What is the impact of exploiting CVE-2003-1422?
Exploiting CVE-2003-1422 allows local users to gain elevated privileges on the affected system.