CVE
- Id
- 5209
- CVE No.
- CVE-2002-0819
- Status
- Candidate
- Description
- Format string vulnerability in artsd, when called by artswrapper, allows local users to gain privileges via format strings in the -a argument, which results in an error message that is not properly handled in a call to the arts_fatal function.
- Phase
- Proposed (20020830)
- Votes
- ACCEPT(1) Baker | MODIFY(1) Frech | NOOP(3) Cole, Cox, Wall | REJECT(1) Foat
- Comments
- Foat> Artsd was supposedly vulnerable to a format string vulneraibity | resulting in elevated privileges because it called command (artscontrol) and was | installed suid root. The problem was supposed to affect Red Hat 7.2. We looked | at two different install of 7.2, neither of which had artsd nor artscontrol | installed suid root. | Frech> XF:artswrapper-artsd-format-string(9813)