Vulnerability Description
Buffer overflow in xpcd-svga for xpcd 2.08 and earlier allows local users to execute arbitrary code via a long HOME environment variable.
CVSS Score
7.2
HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Xpcd | Xpcd | <= 2.08 |
References
- http://www.debian.org/security/2003/dsa-368PatchVendor Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2004:053
- http://www.debian.org/security/2003/dsa-368PatchVendor Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2004:053
FAQ
What is CVE-2003-0649?
CVE-2003-0649 is a vulnerability with a CVSS score of 7.2 (HIGH). Buffer overflow in xpcd-svga for xpcd 2.08 and earlier allows local users to execute arbitrary code via a long HOME environment variable.
How severe is CVE-2003-0649?
CVE-2003-0649 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2003-0649?
Check the references section above for vendor advisories and patch information. Affected products include: Xpcd Xpcd.