CVE-2003-0098
published 2003-03-03CVE-2003-0098: Unknown vulnerability in apcupsd before 3.8.6, and 3.10.x before 3.10.5, allows remote attackers to gain root privileges, possibly via format strings in a…
PriorityP342critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
5.17%
91.6th percentile
Unknown vulnerability in apcupsd before 3.8.6, and 3.10.x before 3.10.5, allows remote attackers to gain root privileges, possibly via format strings in a request to a slave server.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apcupsd | apcupsd | < 3.8.6 | 3.8.6 |
| apcupsd | apcupsd | >= 0 < 3.8.5-1.2 | 3.8.5-1.2 |
| apcupsd | apcupsd | >= 0 < 3.8.5-1.2 | 3.8.5-1.2 |
| apcupsd | apcupsd | >= 0 < 3.8.5-1.2 | 3.8.5-1.2 |
| apcupsd | apcupsd | >= 0 < 3.8.5-1.2 | 3.8.5-1.2 |
| apcupsd | apcupsd | >= 3.10.0 < 3.10.5 | 3.10.5 |
| debian | apcupsd | < apcupsd 3.8.5-1.2 (bookworm) | apcupsd 3.8.5-1.2 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9xf5-hxpg-rcfj: Unknown vulnerability in apcupsd before 3
ghsa_unreviewed·2022-05-03
CVE-2003-0098 [HIGH] GHSA-9xf5-hxpg-rcfj: Unknown vulnerability in apcupsd before 3
Unknown vulnerability in apcupsd before 3.8.6, and 3.10.x before 3.10.5, allows remote attackers to gain root privileges, possibly via format strings in a request to a slave server.
OSV
CVE-2003-0098: Unknown vulnerability in apcupsd before 3
osv·2003-03-03·CVSS 10.0
CVE-2003-0098 [CRITICAL] CVE-2003-0098: Unknown vulnerability in apcupsd before 3
Unknown vulnerability in apcupsd before 3.8.6, and 3.10.x before 3.10.5, allows remote attackers to gain root privileges, possibly via format strings in a request to a slave server.
Debian
CVE-2003-0098: apcupsd - Unknown vulnerability in apcupsd before 3.8.6, and 3.10.x before 3.10.5, allows ...
vendor_debian·2003·CVSS 10.0
CVE-2003-0098 [CRITICAL] CVE-2003-0098: apcupsd - Unknown vulnerability in apcupsd before 3.8.6, and 3.10.x before 3.10.5, allows ...
Unknown vulnerability in apcupsd before 3.8.6, and 3.10.x before 3.10.5, allows remote attackers to gain root privileges, possibly via format strings in a request to a slave server.
Scope: local
bookworm: resolved (fixed in 3.8.5-1.2)
bullseye: resolved (fixed in 3.8.5-1.2)
forky: resolved (fixed in 3.8.5-1.2)
sid: resolved (fixed in 3.8.5-1.2)
trixie: resolved (fixed in 3.8.5-1.2)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-015.0.txthttp://cvs.sourceforge.net/cgi-bin/viewcvs.cgi/apcupsd/apcupsd/src/apcnisd.c.diff?r1=1.5&r2=1.6http://hsj.shadowpenguin.org/misc/apcupsd_exp.txthttp://securitytracker.com/id?1006108http://sourceforge.net/project/shownotes.php?release_id=137900http://www.debian.org/security/2003/dsa-277http://www.iss.net/security_center/static/11334.phphttp://www.mandriva.com/security/advisories?name=MDKSA-2003:018http://www.novell.com/linux/security/advisories/2003_022_apcupsd.htmlhttp://www.securityfocus.com/bid/6828http://www.securityfocus.com/bid/7200ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2003-015.0.txthttp://cvs.sourceforge.net/cgi-bin/viewcvs.cgi/apcupsd/apcupsd/src/apcnisd.c.diff?r1=1.5&r2=1.6http://hsj.shadowpenguin.org/misc/apcupsd_exp.txthttp://securitytracker.com/id?1006108http://sourceforge.net/project/shownotes.php?release_id=137900http://www.debian.org/security/2003/dsa-277http://www.iss.net/security_center/static/11334.phphttp://www.mandriva.com/security/advisories?name=MDKSA-2003:018http://www.novell.com/linux/security/advisories/2003_022_apcupsd.htmlhttp://www.securityfocus.com/bid/6828http://www.securityfocus.com/bid/7200
2003-03-03
Published