CVE-2004-0793: High severity Debian Bsdmainutils vulnerability
The calendar program in bsdmainutils 6.0 through 6.0.14 does not drop root privileges when executed with the -a flag, which allows attackers to execute arbitrary commands via a calendar event file.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0793?
CVE-2004-0793 is considered a medium severity vulnerability due to the potential for arbitrary command execution.
How do I fix CVE-2004-0793?
To fix CVE-2004-0793, update bsdmainutils to version 6.0.15 or later, where the vulnerability has been patched.
What systems are affected by CVE-2004-0793?
CVE-2004-0793 affects multiple versions of bsdmainutils from 6.0 to 6.0.14 on Debian systems.
What happens if CVE-2004-0793 is exploited?
If CVE-2004-0793 is exploited, an attacker can execute arbitrary commands with root privileges through a crafted calendar event file.
Is CVE-2004-0793 a remote exploit vulnerability?
CVE-2004-0793 is not a remote exploit vulnerability; it requires local access to the system to execute the malicious calendar event.