CVE-2003-0102

NameCVE-2003-0102
DescriptionBuffer overflow in tryelf() in readelf.c of the file command allows attackers to execute arbitrary code as the user running file, possibly via a large entity size value in an ELF header (elfhdr.e_shentsize).
SourceCVE (at NVD; oss-sec, fulldisc, OSVDB, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, more)
ReferencesDSA-260
NVD severitymedium (attack range: local)
Debian/oldstablenot vulnerable.
Debian/stablenot vulnerable.
Debian/testingnot vulnerable.
Debian/unstablenot vulnerable.

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
file (PTS)squeeze (security), squeeze5.04-5+squeeze5fixed
squeeze (lts)5.04-5+squeeze9fixed
wheezy5.11-2+deb7u6fixed
wheezy (security)5.11-2+deb7u7fixed
jessie1:5.20-2fixed
sid1:5.22+15-1fixed

The information above is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
filesource(unstable)3.40-1.1medium
filesourcewoody3.37-3.1.woody.1mediumDSA-260

Search for package or bug name: Reporting problems