Unrated severityNVD Advisory· Published Feb 21, 2005· Updated Apr 16, 2026
CVE-2005-0503
CVE-2005-0503
Description
uim before 0.4.5.1 trusts certain environment variables when libUIM is used in setuid or setgid applications, which allows local users to gain privileges.
Affected products
3cpe:2.3:o:mandrakesoft:mandrake_linux:10.1:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:mandrakesoft:mandrake_linux:10.1:*:*:*:*:*:*:*
- cpe:2.3:o:mandrakesoft:mandrake_linux:10.1:*:x86_64:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- secunia.com/advisories/13981nvdPatchVendor Advisory
- www.securityfocus.com/bid/12604nvdPatchVendor Advisory
- lists.freedesktop.org/archives/uim/2005-February/000996.htmlnvdVendor Advisory
- www.mandriva.com/security/advisoriesnvd
News mentions
0No linked articles in our index yet.