Vulnerability Description
CRLF injection vulnerability in fvwm-menu-directory for fvwm 2.5.x before 2.5.10 and 2.4.x before 2.4.18 allows local users to execute arbitrary commands via carriage returns in a filename.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fvwm | Fvwm | <= 2.4.17 |
References
- http://www.fvwm.org/news/
- http://www.securityfocus.com/bid/9161ExploitPatch
- http://www.fvwm.org/news/
- http://www.securityfocus.com/bid/9161ExploitPatch
FAQ
What is CVE-2003-1308?
CVE-2003-1308 is a vulnerability with a CVSS score of 4.6 (MEDIUM). CRLF injection vulnerability in fvwm-menu-directory for fvwm 2.5.x before 2.5.10 and 2.4.x before 2.4.18 allows local users to execute arbitrary commands via carriage returns in a filename.
How severe is CVE-2003-1308?
CVE-2003-1308 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2003-1308?
Check the references section above for vendor advisories and patch information. Affected products include: Fvwm Fvwm.