VYPR
Unrated severityNVD Advisory· Published Dec 31, 2003· Updated Jun 16, 2026

CVE-2003-1308

CVE-2003-1308

Description

CRLF injection vulnerability in fvwm-menu-directory for fvwm 2.5.x before 2.5.10 and 2.4.x before 2.4.18 allows local users to execute arbitrary commands via carriage returns in a filename.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Fvwm/Fvwm2 versions
    cpe:2.3:a:fvwm:fvwm:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:fvwm:fvwm:*:*:*:*:*:*:*:*range: <=2.4.17
    • (no CPE)range: >= 2.4.0, < 2.4.18 and >= 2.5.0, < 2.5.10

Patches

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.