Vulnerability Description
Kerberos FTP client allows remote FTP sites to execute arbitrary code via a pipe (|) character in a filename that is retrieved by the client.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mit | Kerberos Ftp Client | All versions |
| Redhat | Linux | 6.2 |
| Mandrakesoft | Mandrake Multi Network Firewall | 8.2 |
| Mandrakesoft | Mandrake Linux | 8.1 |
Related Weaknesses (CWE)
References
- http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0047.htmlBroken Link
- http://secunia.com/advisories/7979Broken Link
- http://secunia.com/advisories/8114Broken Link
- http://www.mandriva.com/security/advisories?name=MDKSA-2003:021Third Party Advisory
- http://www.redhat.com/support/errata/RHSA-2003-020.htmlBroken LinkPatchVendor Advisory
- http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0047.htmlBroken Link
- http://secunia.com/advisories/7979Broken Link
- http://secunia.com/advisories/8114Broken Link
- http://www.mandriva.com/security/advisories?name=MDKSA-2003:021Third Party Advisory
- http://www.redhat.com/support/errata/RHSA-2003-020.htmlBroken LinkPatchVendor Advisory
FAQ
What is CVE-2003-0041?
CVE-2003-0041 is a vulnerability with a CVSS score of 10.0 (HIGH). Kerberos FTP client allows remote FTP sites to execute arbitrary code via a pipe (|) character in a filename that is retrieved by the client.
How severe is CVE-2003-0041?
CVE-2003-0041 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2003-0041?
Check the references section above for vendor advisories and patch information. Affected products include: Mit Kerberos Ftp Client, Redhat Linux, Mandrakesoft Mandrake Multi Network Firewall, Mandrakesoft Mandrake Linux.