CVE Vulnerabilities

CVE-2004-0793

Published: Oct 20, 2004 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The calendar program in bsdmainutils 6.0 through 6.0.14 does not drop root privileges when executed with the -a flag, which allows attackers to execute arbitrary commands via a calendar event file.

Affected Software

NameVendorStart VersionEnd Version
BsdmainutilsDebian6.0 (including)6.0 (including)
BsdmainutilsDebian6.0.1 (including)6.0.1 (including)
BsdmainutilsDebian6.0.2 (including)6.0.2 (including)
BsdmainutilsDebian6.0.3 (including)6.0.3 (including)
BsdmainutilsDebian6.0.4 (including)6.0.4 (including)
BsdmainutilsDebian6.0.5 (including)6.0.5 (including)
BsdmainutilsDebian6.0.6 (including)6.0.6 (including)
BsdmainutilsDebian6.0.7 (including)6.0.7 (including)
BsdmainutilsDebian6.0.8 (including)6.0.8 (including)
BsdmainutilsDebian6.0.9 (including)6.0.9 (including)
BsdmainutilsDebian6.0.10 (including)6.0.10 (including)
BsdmainutilsDebian6.0.11 (including)6.0.11 (including)
BsdmainutilsDebian6.0.12 (including)6.0.12 (including)
BsdmainutilsDebian6.0.13 (including)6.0.13 (including)
BsdmainutilsDebian6.0.14 (including)6.0.14 (including)
BsdmainutilsUbuntudapper*
BsdmainutilsUbuntudevel*
BsdmainutilsUbuntuedgy*
BsdmainutilsUbuntufeisty*

References