CVE-2003-0098
UnknownEPSS 5.13%
Last modified
CVE-2003-0098 is a vulnerability of currently unknown severity. Unknown vulnerability in apcupsd before 3.8.6, and 3.10.x before 3.10.5, allows remote attackers to gain root privileges, possibly via format strings in a request to a slave server.. EPSS estimates a 5.13% chance of exploitation in the next 30 days.
Description
Unknown vulnerability in apcupsd before 3.8.6, and 3.10.x before 3.10.5, allows remote attackers to gain root privileges, possibly via format strings in a request to a slave server.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apcupsd | Apcupsd | < 3.8.6 |
| Apcupsd | Apcupsd | >= 3.10.0, < 3.10.5 |
| Debian | Debian Linux | 2.2 |
| Debian | Debian Linux | 3.0 |
References
- http://cvs.sourceforge.net/cgi-bin/viewcvs.cgi/apcupsd/apcupsd/src/apcnisd.c.diff?r1=1.5&r2=1.6Broken Link, Vendor Advisory
- http://securitytracker.com/id?1006108Third Party Advisory, VDB Entry
- http://www.debian.org/security/2003/dsa-277Patch, Vendor Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2003:018Third Party Advisory
- http://www.securityfocus.com/bid/6828Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/7200Third Party Advisory, VDB Entry
- http://cvs.sourceforge.net/cgi-bin/viewcvs.cgi/apcupsd/apcupsd/src/apcnisd.c.diff?r1=1.5&r2=1.6Broken Link, Vendor Advisory
- http://securitytracker.com/id?1006108Third Party Advisory, VDB Entry
- http://www.debian.org/security/2003/dsa-277Patch, Vendor Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2003:018Third Party Advisory
- http://www.securityfocus.com/bid/6828Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/7200Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2003-0098?
Unknown vulnerability in apcupsd before 3.8.6, and 3.10.x before 3.10.5, allows remote attackers to gain root privileges, possibly via format strings in a request to a slave server.
How severe is CVE-2003-0098?
Severity scoring for CVE-2003-0098 is pending analysis. The EPSS model estimates a 5.13% probability of exploitation in the next 30 days.
How do I fix CVE-2003-0098?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2003
- CVE-2003-0092Heap-based buffer overflow in dtsession for Solaris 2.5.1 th…
- CVE-2003-0093The RADIUS decoder in tcpdump 3.6.2 and earlier allows remot…
- CVE-2003-0094A patch for mcookie in the util-linux package for Mandrake L…
- CVE-2003-0095Buffer overflow in ORACLE.EXE for Oracle Database Server 9i,…
- CVE-2003-0096Multiple buffer overflows in Oracle 9i Database release 2, R…
- CVE-2003-0097Unknown vulnerability in CGI module for PHP 4.3.0 allows att…
- CVE-2003-0099Multiple buffer overflows in apcupsd before 3.8.6, and 3.10.…
- CVE-2003-0100Buffer overflow in Cisco IOS 11.2.x to 12.0.x allows remote …
- CVE-2003-0101miniserv.pl in (1) Webmin before 1.070 and (2) Usermin befor…
- CVE-2003-0102Buffer overflow in tryelf() in readelf.c of the file command…
- CVE-2003-0103Format string vulnerability in Nokia 6210 handset allows rem…
- CVE-2003-0104Directory traversal vulnerability in PeopleTools 8.10 throug…
Are you affected by CVE-2003-0098?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
