DEBIAN-CVE-2003-1294

Source
https://security-tracker.debian.org/tracker/DEBIAN-CVE-2003-1294
Import Source
https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2003-1294.json
JSON Data
https://api.test.osv.dev/v1/vulns/DEBIAN-CVE-2003-1294
Upstream
Published
2003-12-31T05:00:00Z
Modified
2025-09-19T06:25:30Z
Summary
[none]
Details

Xscreensaver before 4.15 creates temporary files insecurely in (1) driver/passwd-kerberos.c, (2) driver/xscreensaver-getimage-video, (3) driver/xscreensaver.kss.in, and the (4) vidwhacker and (5) webcollage screensavers, which allows local users to overwrite arbitrary files via a symlink attack.

References

Affected packages

Debian:11 / xscreensaver

Package

Name
xscreensaver
Purl
pkg:deb/debian/xscreensaver?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.15-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / xscreensaver

Package

Name
xscreensaver
Purl
pkg:deb/debian/xscreensaver?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.15-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / xscreensaver

Package

Name
xscreensaver
Purl
pkg:deb/debian/xscreensaver?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.15-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:14 / xscreensaver

Package

Name
xscreensaver
Purl
pkg:deb/debian/xscreensaver?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.15-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}