CVE-2003-0885
Last modified
CVE-2003-0885 is a vulnerability of currently unknown severity. Xscreensaver 4.14 contains certain debugging code that should have been omitted, which causes Xscreensaver to create temporary files insecurely in the (1) apple2, (2) xanalogtv, and (3) pong screensavers, and allows local users to overwrite arbitrary files via a symlink attack.. EPSS estimates a 1.30% chance of exploitation in the next 30 days.
Description
Xscreensaver 4.14 contains certain debugging code that should have been omitted, which causes Xscreensaver to create temporary files insecurely in the (1) apple2, (2) xanalogtv, and (3) pong screensavers, and allows local users to overwrite arbitrary files via a symlink attack.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Xscreensaver | Xscreensaver | 4.14 |
References
- http://bugs.gentoo.org/show_bug.cgi?id=41253Exploit, Patch, Vendor Advisory
- http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=182286Vendor Advisory
- http://bugs.gentoo.org/show_bug.cgi?id=41253Exploit, Patch, Vendor Advisory
- http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=182286Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2003-0885?
How severe is CVE-2003-0885?
How do I fix CVE-2003-0885?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2003
- CVE-2003-0878slpd daemon in Mac OS X before 10.3 allows local users to ov…
- CVE-2003-0879Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2003-0880Unknown vulnerability in Mac OS X before 10.3 allows local u…
- CVE-2003-0881Mail in Mac OS X before 10.3, when configured to use MD5 Cha…
- CVE-2003-0882Mac OS X before 10.3 initializes the TCP timestamp with a co…
- CVE-2003-0883The System Preferences capability in Mac OS X before 10.3 al…
- CVE-2003-0886Format string vulnerability in hfaxd for Hylafax 4.1.7 and e…
- CVE-2003-0887ez-ipupdate 3.0.11b7 and earlier creates insecure temporary …
- CVE-2003-0894Buffer overflow in the (1) oracle and (2) oracleO programs i…
- CVE-2003-0895Buffer overflow in the Mac OS X kernel 10.2.8 and earlier al…
- CVE-2003-0896The loadClass method of the sun.applet.AppletClassLoader cla…
- CVE-2003-0897"Shatter" vulnerability in CommCtl32.dll in Windows XP may a…
Are you affected by CVE-2003-0885?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
