CVE-2003-0333
Multiple buffer overflows in kermit in HP-UX 10.20 and 11.00 (C-Kermit 6.0.192 and possibly other versions before 8.0) allow local users to gain privileges via long arguments to (1) ask, (2) askq, (3) define, (4) assign, and (5) getc, some of which may…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.65%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple buffer overflows in kermit in HP-UX 10.20 and 11.00 (C-Kermit 6.0.192 and possibly other versions before 8.0) allow local users to gain privileges via long arguments to (1) ask, (2) askq, (3) define, (4) assign, and (5) getc, some of which may share the same underlying function "doask," a different vulnerability than CVE-2001-0085.
- CVSS 2.0
- 7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 0.65% probability · 49th percentile
- CISA KEV
- Not listed
- Affected
- hp/hp-ux
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/hp/current/0044.html
- http://marc.info/?l=bugtraq&m=105189670912220&w=2
- http://marc.info/?l=bugtraq&m=105190667523456&w=2
- http://www.kb.cert.org/vuls/id/971364Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/7627Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11929
- http://archives.neohapsis.com/archives/hp/current/0044.html
- http://marc.info/?l=bugtraq&m=105189670912220&w=2
- http://marc.info/?l=bugtraq&m=105190667523456&w=2
- http://www.kb.cert.org/vuls/id/971364Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/7627Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11929
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.