CVE-2003-0337

UnknownEPSS 0.32%

Last modified

CVE-2003-0337 is a vulnerability of currently unknown severity. The ckconfig command in lsadmin for Load Sharing Facility (LSF) 5.1 allows local users to execute arbitrary programs by modifying the LSF_ENVDIR environment variable to reference an alternate lsf.conf file, then modifying LSF_SERVERDIR to point to a malicious lim program, which lsadmin then executes.. EPSS estimates a 0.32% chance of exploitation in the next 30 days.

Description

The ckconfig command in lsadmin for Load Sharing Facility (LSF) 5.1 allows local users to execute arbitrary programs by modifying the LSF_ENVDIR environment variable to reference an alternate lsf.conf file, then modifying LSF_SERVERDIR to point to a malicious lim program, which lsadmin then executes.

Metrics

EPSS Probability
0.32%

23.8th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
PlatformLsadmin5.1

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2003-0337?
The ckconfig command in lsadmin for Load Sharing Facility (LSF) 5.1 allows local users to execute arbitrary programs by modifying the LSF_ENVDIR environment variable to reference an alternate lsf.conf file, then modifying LSF_SERVERDIR to point to a malicious lim program, which lsadmin then executes.
How severe is CVE-2003-0337?
Severity scoring for CVE-2003-0337 is pending analysis. The EPSS model estimates a 0.32% probability of exploitation in the next 30 days.
How do I fix CVE-2003-0337?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2003-0337?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST