VulnerabilityModified
CVE-2001-0803
Buffer overflow in the client connection routine of libDtSvc.so.1 in CDE Subprocess Control Service (dtspcd) allows remote attackers to execute arbitrary commands.
HIGH 10.0EPSS 85.6%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 85.6%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
Buffer overflow in the client connection routine of libDtSvc.so.1 in CDE Subprocess Control Service (dtspcd) allows remote attackers to execute arbitrary commands.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 85.56% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- open group/cde common desktop environment
- Source
- cve@mitre.org
References
- ftp://patches.sgi.com/support/free/security/advisories/20011107-01-P
- ftp://stage.caldera.com/pub/security/openunix/CSSA-2001-SCO.30/
- http://ftp.support.compaq.com/patches/.new/html/SSRT-541.shtml
- http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/214
- http://www.cert.org/advisories/CA-2001-31.htmlUS Government Resource
- http://www.cert.org/advisories/CA-2002-01.htmlUS Government Resource
- http://www.kb.cert.org/vuls/id/172583Patch, Third Party Advisory, US Government Resource
- http://www.securityfocus.com/advisories/3651Patch, Vendor Advisory
- http://www.securityfocus.com/bid/3517Patch, Vendor Advisory
- http://xforce.iss.net/alerts/advise101.phpVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7396
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A70
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A74
- ftp://patches.sgi.com/support/free/security/advisories/20011107-01-P
- ftp://stage.caldera.com/pub/security/openunix/CSSA-2001-SCO.30/
- http://ftp.support.compaq.com/patches/.new/html/SSRT-541.shtml
- http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/214
- http://www.cert.org/advisories/CA-2001-31.htmlUS Government Resource
- http://www.cert.org/advisories/CA-2002-01.htmlUS Government Resource
- http://www.kb.cert.org/vuls/id/172583Patch, Third Party Advisory, US Government Resource
- http://www.securityfocus.com/advisories/3651Patch, Vendor Advisory
- http://www.securityfocus.com/bid/3517Patch, Vendor Advisory
- http://xforce.iss.net/alerts/advise101.phpVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7396
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A70
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A74
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.