PT-2003-1938 · Unknown · Xscreensaver
Stan Bubrouski
·
Publicado
2003-12-31
·
Atualizado
2008-09-05
·
CVE-2003-0885
CVSS v2.0
6.4
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Xscreensaver version 4.14
Description
The issue is related to certain debugging code that was not removed from Xscreensaver, leading to insecure creation of temporary files in the apple2, xanalogtv, and pong screensavers. This allows local users to overwrite arbitrary files via a symlink attack.
Recommendations
For Xscreensaver version 4.14, consider removing or disabling the affected screensavers (apple2, xanalogtv, and pong) until a patch is available to prevent local users from exploiting this issue.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Xscreensaver