CVE-2003-1399

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
31/12/2003
Last modified:
03/04/2025

Description

eject 2.0.10, when installed setuid on systems such as SuSE Linux 7.3, generates different error messages depending on whether a specified file exists or not, which allows local users to obtain sensitive information.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:eject:eject:2.0.10:*:*:*:*:*:*:*
cpe:2.3:a:eject:eject:2.0.11:*:*:*:*:*:*:*
cpe:2.3:a:eject:eject:2.0.12:*:*:*:*:*:*:*