Vulnerabilities > CVE-2003-1308 - Unspecified vulnerability in Fvwm

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
fvwm
exploit available

Summary

CRLF injection vulnerability in fvwm-menu-directory for fvwm 2.5.x before 2.5.10 and 2.4.x before 2.4.18 allows local users to execute arbitrary commands via carriage returns in a filename.

Vulnerable Configurations

Part Description Count
Application
Fvwm
1

Exploit-Db

descriptionFVWM 2.4/2.5 fvwm-menu-directory Command Execution Vulnerability. CVE-2003-1308 . Local exploit for linux platform
idEDB-ID:23414
last seen2016-02-02
modified2003-12-05
published2003-12-05
reporterauto22238
sourcehttps://www.exploit-db.com/download/23414/
titleFVWM 2.4/2.5 fvwm-menu-directory Command Execution Vulnerability

Statements

contributorMark J Cox
lastmodified2006-11-22
organizationRed Hat
statementNot vulnerable. Red Hat Enterprise Linux 2.1 shipped with fvwm, however this issue does not affect the included version of fvwm.