CVE-2003-0947

Severity CVSS v4.0:
Pending analysis
Type:
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
15/12/2003
Last modified:
21/06/2022

Description

Buffer overflow in iwconfig, when installed setuid, allows local users to execute arbitrary code via a long OUT environment variable.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:wireless_tools_project:wireless_tools:19:*:*:*:*:*:*:*
cpe:2.3:a:wireless_tools_project:wireless_tools:20:*:*:*:*:*:*:*
cpe:2.3:a:wireless_tools_project:wireless_tools:21:*:*:*:*:*:*:*
cpe:2.3:a:wireless_tools_project:wireless_tools:22:*:*:*:*:*:*:*
cpe:2.3:a:wireless_tools_project:wireless_tools:23:*:*:*:*:*:*:*
cpe:2.3:a:wireless_tools_project:wireless_tools:24:*:*:*:*:*:*:*
cpe:2.3:a:wireless_tools_project:wireless_tools:25:*:*:*:*:*:*:*
cpe:2.3:a:wireless_tools_project:wireless_tools:26:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools