Vulnerability Name:

CVE-2002-0044 (CCN-7932)

Assigned:2002-01-18
Published:2002-01-18
Updated:2017-10-10
Summary:GNU Enscript 1.6.1 and earlier allows local users to overwrite arbitrary files of the Enscript user via a symlink attack on temporary files.
CVSS v3 Severity:4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:3.6 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): None
2.6 Low (CCN CVSS v2 Vector: AV:L/AC:H/Au:N/C:N/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): High
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-Other
Vulnerability Consequences:File Manipulation
References:Source: MITRE
Type: CNA
CVE-2002-0044

Source: CCN
Type: Hewlett-Packard Company Security Bulletin HPSBTL0201-019
Updated enscript packages available

Source: CCN
Type: RHSA-2002-012
Updated enscript packages fix temporary file handling vulnerabilities

Source: DEBIAN
Type: UNKNOWN
DSA-105

Source: DEBIAN
Type: DSA-105
enscript -- insecure temporary files

Source: MANDRAKE
Type: UNKNOWN
MDKSA-2002:010

Source: CCN
Type: OSVDB ID: 2030
GNU Enscript Insecure Temporary File Creation

Source: REDHAT
Type: UNKNOWN
RHSA-2002:012

Source: HP
Type: UNKNOWN
HPSBTL0201-019

Source: BID
Type: UNKNOWN
3920

Source: CCN
Type: BID-3920
GNU Enscript Insecure Temporary File Creation Vulnerability

Source: XF
Type: UNKNOWN
gnu-enscript-tmpfile-symlink(7932)

Source: XF
Type: UNKNOWN
gnu-enscript-tmpfile-symlink(7932)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:gnu:enscript:*:*:*:*:*:*:*:* (Version <= 1.6.1)

  • Configuration 2:
  • cpe:/o:debian:debian_linux:2.2:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:linux:6.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:linux:6.1:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:linux:6.2:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:linux:7.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:linux:7.1:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:linux:7.2:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:gnu:enscript:1.6.1:*:*:*:*:*:*:*
  • AND
  • cpe:/o:redhat:linux:6.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:linux:6.1:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:linux:6.2:*:*:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:2.2:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:7.1:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:linux:7:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:7.2:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux_corporate_server:1.0.1:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:linux:7.1:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:8.0:*:*:*:*:*:*:*
  • OR cpe:/o:mandrakesoft:mandrake_linux:8.1:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:linux:7.2:*:*:*:*:*:*:*
  • OR cpe:/o:hp:secure_os:1.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:linux:7.3:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.debian:def:105
    V
    insecure temporary files
    2002-01-21
    BACK
    gnu enscript *
    debian debian linux 2.2
    redhat linux 6.0
    redhat linux 6.1
    redhat linux 6.2
    redhat linux 7.0
    redhat linux 7.1
    redhat linux 7.2
    gnu enscript 1.6.1
    redhat linux 6.0
    redhat linux 6.1
    redhat linux 6.2
    debian debian linux 2.2
    mandrakesoft mandrake linux 7.1
    redhat linux 7
    mandrakesoft mandrake linux 7.2
    mandrakesoft mandrake linux corporate server 1.0.1
    redhat linux 7.1
    mandrakesoft mandrake linux 8.0
    mandrakesoft mandrake linux 8.1
    redhat linux 7.2
    hp secure os 1.0
    redhat linux 7.3