PT-2003-1938 · Unknown · Xscreensaver

Stan Bubrouski

·

Publicado

2003-12-31

·

Atualizado

2008-09-05

·

CVE-2003-0885

CVSS v2.0

6.4

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions Xscreensaver version 4.14
Description The issue is related to certain debugging code that was not removed from Xscreensaver, leading to insecure creation of temporary files in the apple2, xanalogtv, and pong screensavers. This allows local users to overwrite arbitrary files via a symlink attack.
Recommendations For Xscreensaver version 4.14, consider removing or disabling the affected screensavers (apple2, xanalogtv, and pong) until a patch is available to prevent local users from exploiting this issue.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2003-0885

Produtos afetados

Xscreensaver