CVE-2003-0359
EPSS 0.32%
Description
nethack 3.4.0 and earlier installs certain setgid binaries with insecure permissions, which allows local users to gain privileges by replacing the original binaries with malicious code.
How to fix CVE-2003-0359
To remediate CVE-2003-0359, upgrade the affected package to a fixed version below.
- Debian/nethack—upgrade to 3.4.1-1 or later
- Debian/slashem—upgrade to 0.0.6E4F8-6 or later
Is CVE-2003-0359 being exploited?
Low — EPSS is 0.3%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 3.4.1-1
- from 0, < 0.0.6E4F8-6