Vulnerabilities > CVE-2003-0648
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Multiple buffer overflows in vfte, based on FTE, before 0.50, allow local users to execute arbitrary code.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 | |
OS | 1 |
Nessus
NASL family | Debian Local Security Checks |
NASL id | DEBIAN_DSA-472.NASL |
description | Steve Kemp and Jaguar discovered a number of buffer overflow vulnerabilities in vfte, a version of the fte editor which runs on the Linux console, found in the package fte-console. This program is setuid root in order to perform certain types of low-level operations on the console. Due to these bugs, setuid privilege has been removed from vfte, making it only usable by root. We recommend using the terminal version (in the fte-terminal package) instead, which runs on any capable terminal including the Linux console. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 15309 |
published | 2004-09-29 |
reporter | This script is Copyright (C) 2004-2019 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/15309 |
title | Debian DSA-472-1 : fte - several vulnerabilities |
code |
|
References
- http://secunia.com/advisories/11290
- http://secunia.com/advisories/11290
- http://securitytracker.com/id?1009655
- http://securitytracker.com/id?1009655
- http://securitytracker.com/id?1009656
- http://securitytracker.com/id?1009656
- http://www.debian.org/security/2004/dsa-472
- http://www.debian.org/security/2004/dsa-472
- http://www.kb.cert.org/vuls/id/354838
- http://www.kb.cert.org/vuls/id/354838
- http://www.kb.cert.org/vuls/id/900964
- http://www.kb.cert.org/vuls/id/900964
- http://www.securityfocus.com/bid/10041
- http://www.securityfocus.com/bid/10041
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15726
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15726