CVE Vulnerabilities

CVE-2003-0102

Published: Mar 18, 2003 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Buffer overflow in tryelf() in readelf.c of the file command allows attackers to execute arbitrary code as the user running file, possibly via a large entity size value in an ELF header (elfhdr.e_shentsize).

Affected Software

NameVendorStart VersionEnd Version
FileFile3.28 (including)3.28 (including)
FileFile3.30 (including)3.30 (including)
FileFile3.32 (including)3.32 (including)
FileFile3.33 (including)3.33 (including)
FileFile3.34 (including)3.34 (including)
FileFile3.35 (including)3.35 (including)
FileFile3.36 (including)3.36 (including)
FileFile3.37 (including)3.37 (including)
FileFile3.39 (including)3.39 (including)
FileFile3.40 (including)3.40 (including)
Red Hat Enterprise Linux AS (Advanced Server) version 2.1RedHat*
Red Hat Enterprise Linux ES version 2.1RedHat*
Red Hat Enterprise Linux WS version 2.1RedHat*
Red Hat Linux 6.2RedHat*
Red Hat Linux 7.0RedHat*
Red Hat Linux 7.1RedHat*
Red Hat Linux 7.2RedHat*
Red Hat Linux 7.3RedHat*
Red Hat Linux 8.0RedHat*
Red Hat Linux Advanced Workstation 2.1RedHat*
FileUbuntudapper*
FileUbuntudevel*
FileUbuntuedgy*
FileUbuntufeisty*

References