Vulnerabilities > CVE-2003-0262 - Multiple Unspecified vulnerability in Leksbot 1.2

047910
CVSS 7.2 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
low complexity
leksbot
nessus
exploit available

Summary

leksbot 1.2.3 in Debian GNU/Linux installs the KATAXWR as setuid root, which allows local users to gain root privileges by exploiting unknown vulnerabilities related to the escalated privileges, which KATAXWR is not designed to have.

Vulnerable Configurations

Part Description Count
Application
Leksbot
1

Exploit-Db

descriptionLeksbot 1.2 Multiple Unspecified Vulnerabilities. CVE-2003-0262. Local exploit for linux platform
idEDB-ID:22567
last seen2016-02-02
modified2003-05-06
published2003-05-06
reportergunzip
sourcehttps://www.exploit-db.com/download/22567/
titleLeksbot 1.2 - Multiple Unspecified Vulnerabilities

Nessus

NASL familyDebian Local Security Checks
NASL idDEBIAN_DSA-299.NASL
descriptionMaurice Massar discovered that, due to a packaging error, the program /usr/bin/KATAXWR was inadvertently installed setuid root. This program was not designed to run setuid, and contained multiple vulnerabilities which could be exploited to gain root privileges.
last seen2020-06-01
modified2020-06-02
plugin id15136
published2004-09-29
reporterThis script is Copyright (C) 2004-2019 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/15136
titleDebian DSA-299-1 : leksbot - improper setuid-root execution