7.2
CVE-2003-0947
- EPSS 1.3%
- Veröffentlicht 15.12.2003 05:00:00
- Zuletzt bearbeitet 16.06.2026 22:03:13
- Erkennungen
Buffer overflow in iwconfig, when installed setuid, allows local users to execute arbitrary code via a long OUT environment variable.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wireless Tools Project ≫ Wireless Tools Version 19
Wireless Tools Project ≫ Wireless Tools Version 20
Wireless Tools Project ≫ Wireless Tools Version 21
Wireless Tools Project ≫ Wireless Tools Version 22
Wireless Tools Project ≫ Wireless Tools Version 23
Wireless Tools Project ≫ Wireless Tools Version 24
Wireless Tools Project ≫ Wireless Tools Version 25
Wireless Tools Project ≫ Wireless Tools Version 26
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.3% | 0.667 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
http://marc.info/?l=bugtraq&m=106867458902521&w=2