Executive Summary

Summary
Title Updated XFree86 packages provide security and bug fixes
Informations
Name RHSA-2003:289 First vendor Publication 2003-11-12
Vendor RedHat Last vendor Modification 2003-11-12
Severity (Vendor) N/A Revision 00

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:N/C:C/I:C/A:C)
Cvss Base Score 10 Attack Range Network
Cvss Impact Score 10 Attack Complexity Low
Cvss Expoit Score 10 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Problem Description:

Original Source

Url : https://rhn.redhat.com/errata/RHSA-2003-289.html

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:193
 
Oval ID: oval:org.mitre.oval:def:193
Title: KDM pam_setcred Privilege Escalation Vulnerability
Description: KDM in KDE 3.1.3 and earlier does not verify whether the pam_setcred function call succeeds, which may allow attackers to gain root privileges by triggering error conditions within PAM modules, as demonstrated in certain configurations of the MIT pam_krb5 module.
Family: unix Class: vulnerability
Reference(s): CVE-2003-0690
Version: 2
Platform(s): Red Hat Linux 9
Product(s): KDM
Definition Synopsis:

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 2
Os 27
Os 6

OpenVAS Exploits

Date Description
2008-09-24 Name : Gentoo Security Advisory GLSA 200311-01 (kdebase)
File : nvt/glsa_200311_01.nasl
2008-01-17 Name : Debian Security Advisory DSA 380-1 (xfree86)
File : nvt/deb_380_1.nasl
2008-01-17 Name : Debian Security Advisory DSA 388-1 (kdebase)
File : nvt/deb_388_1.nasl
2008-01-17 Name : Debian Security Advisory DSA 443-1 (xfree86)
File : nvt/deb_443_1.nasl

Open Source Vulnerability Database (OSVDB)

Id Description
10249 XFree Font Libraries Multiple Unspecified Local Overflows

4773 KDE KDM pam_setcred() Function Error Condition Privilege Escalation

Nessus® Vulnerability Scanner

Date Description
2004-09-29 Name : The remote Debian host is missing a security-related update.
File : debian_DSA-380.nasl - Type : ACT_GATHER_INFO
2004-09-29 Name : The remote Debian host is missing a security-related update.
File : debian_DSA-388.nasl - Type : ACT_GATHER_INFO
2004-09-29 Name : The remote Debian host is missing a security-related update.
File : debian_DSA-443.nasl - Type : ACT_GATHER_INFO
2004-07-31 Name : The remote Mandrake Linux host is missing one or more security updates.
File : mandrake_MDKSA-2003-089.nasl - Type : ACT_GATHER_INFO
2004-07-31 Name : The remote Mandrake Linux host is missing one or more security updates.
File : mandrake_MDKSA-2003-091.nasl - Type : ACT_GATHER_INFO
2004-07-31 Name : The remote Mandrake Linux host is missing one or more security updates.
File : mandrake_MDKSA-2003-118.nasl - Type : ACT_GATHER_INFO
2004-07-06 Name : The remote Red Hat host is missing one or more security updates.
File : redhat-RHSA-2003-270.nasl - Type : ACT_GATHER_INFO
2004-07-06 Name : The remote Red Hat host is missing one or more security updates.
File : redhat-RHSA-2003-289.nasl - Type : ACT_GATHER_INFO

Alert History

If you want to see full details history, please login or register.
0
Date Informations
2014-02-17 11:48:15
  • Multiple Updates