PT-2003-1938 · Unknown · Xscreensaver
Stan Bubrouski
·
Published
2003-12-31
·
Updated
2008-09-05
·
CVE-2003-0885
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Xscreensaver version 4.14
Description
The issue is related to certain debugging code that was not removed from Xscreensaver, leading to insecure creation of temporary files in the apple2, xanalogtv, and pong screensavers. This allows local users to overwrite arbitrary files via a symlink attack.
Recommendations
For Xscreensaver version 4.14, consider removing or disabling the affected screensavers (apple2, xanalogtv, and pong) until a patch is available to prevent local users from exploiting this issue.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Xscreensaver