First published: Wed Dec 31 2003(Updated: )
susehelp in SuSE Linux 8.1, Enterprise Server 8, Office Server, and Openexchange Server 4 does not properly filter shell metacharacters, which allows remote attackers to execute arbitrary commands via CGI queries.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SUSE Linux Office Server | ||
SUSE Linux | =8 | |
SUSE Linux Openexchange Server | =4.0 | |
SUSE Linux | =8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-1538 is classified as a critical vulnerability due to the potential for arbitrary command execution by remote attackers.
To fix CVE-2003-1538, upgrade the affected SuSE Linux versions to the latest patched releases provided by the vendor.
CVE-2003-1538 affects SuSE Linux versions 8.0, 8.1, Enterprise Server 8, Office Server, and Openexchange Server 4.
CVE-2003-1538 can be exploited through specially crafted CGI queries that include shell metacharacters.
Yes, CVE-2003-1538 can lead to data compromise if attackers successfully execute arbitrary commands on the vulnerable systems.