Description
Buffer overflow in the client connection routine of libDtSvc.so.1 in CDE Subprocess Control Service (dtspcd) allows remote attackers to execute arbitrary commands.
Products
- Open Group CDE Common Desktop Environment 1.0.1
- Open Group CDE Common Desktop Environment 1.0.2
- Open Group CDE Common Desktop Environment 1.1
- Open Group CDE Common Desktop Environment 1.2
- Open Group CDE Common Desktop Environment 2.0
- Open Group CDE Common Desktop Environment 2.1
Questions to Ask Vendors
- Can you confirm whether your systems are affected by CVE-2001-0803, and if so, what steps are you currently taking to mitigate this vulnerability?
- What is your estimated timeline for fully resolving CVE-2001-0803 in your products or services, and how will you communicate updates on this issue to us as your customer?
Recommended Actions
- Check out the advisory links provided below.
References