Vulnerability Description
cnd.c in mgetty 1.1.28 and earlier does not properly filter non-printable characters and quotes, which may allow remote attackers to execute arbitrary commands via shell metacharacters in (1) caller ID or (2) caller name strings.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gert Doering | Mgetty | <= 1.1.28 |
References
- ftp://alpha.greenie.net/pub/mgetty/source/1.1/mgetty1.1.29-Nov25.tar.gzPatch
- ftp://alpha.greenie.net/pub/mgetty/source/1.1/mgetty1.1.29-Nov25.tar.gzPatch
FAQ
What is CVE-2003-0516?
CVE-2003-0516 is a vulnerability with a CVSS score of 7.5 (HIGH). cnd.c in mgetty 1.1.28 and earlier does not properly filter non-printable characters and quotes, which may allow remote attackers to execute arbitrary commands via shell metacharacters in (1) caller I...
How severe is CVE-2003-0516?
CVE-2003-0516 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2003-0516?
Check the references section above for vendor advisories and patch information. Affected products include: Gert Doering Mgetty.