CVE Vulnerabilities

CVE-2003-0703

Published: Sep 17, 2003 | Modified: Jul 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

KisMAC before 0.05d trusts user-supplied variables to load arbitrary kernels or kernel modules, which allows local users to gain privileges via the $DRIVER_KEXT environment variable as used in (1) viha_driver.sh, (2) macjack_load.sh, or (3) airojack_load.sh, or (4) via similar techniques using exchangeKernel.sh.

Affected Software

Name Vendor Start Version End Version
Kismac Kismac 0.05d (including) 0.05d (including)

References