Vulnerability Name: | CVE-2003-0924 (CCN-14874) | ||||||||||||||||||||||||||||
Assigned: | 2004-01-18 | ||||||||||||||||||||||||||||
Published: | 2004-01-18 | ||||||||||||||||||||||||||||
Updated: | 2017-10-10 | ||||||||||||||||||||||||||||
Summary: | netpbm 9.25 and earlier does not properly create temporary files, which allows local users to overwrite arbitrary files. | ||||||||||||||||||||||||||||
CVSS v3 Severity: | 4.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||||||||||||||||||
CVSS v2 Severity: | 3.7 Low (CVSS v2 Vector: AV:L/AC:H/Au:N/C:P/I:P/A:P)
| ||||||||||||||||||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||||||||||||||||||
Vulnerability Consequences: | File Manipulation | ||||||||||||||||||||||||||||
References: | Source: SGI Type: UNKNOWN 20040201-01-U Source: MITRE Type: CNA CVE-2003-0924 Source: CCN Type: Conectiva Linux Security Announcement CLSA-2004:909 netpbm Source: CCN Type: RHSA-2004-030 Updated NetPBM packages fix multiple temporary file vulnerabilities Source: CCN Type: RHSA-2004-031 netpbm security update Source: CCN Type: SourceForge.net SourceForge.net: Project Info - Netpbm - graphics tools and converters Source: DEBIAN Type: Patch, Vendor Advisory DSA-426 Source: DEBIAN Type: DSA-426 netpbm-free -- insecure temporary files Source: CCN Type: GLSA-200410-02 Netpbm: Multiple temporary file issues Source: GENTOO Type: UNKNOWN GLSA-200410-02 Source: CCN Type: US-CERT VU#487102 Multiple tools within the Netpbm package create temporary files in an insecure manner Source: CERT-VN Type: Third Party Advisory, US Government Resource VU#487102 Source: MANDRAKE Type: UNKNOWN MDKSA-2004:011 Source: REDHAT Type: Patch, Vendor Advisory RHSA-2004:030 Source: REDHAT Type: UNKNOWN RHSA-2004:031 Source: BID Type: Vendor Advisory 9442 Source: CCN Type: BID-9442 Netpbm Temporary File Vulnerabilities Source: CCN Type: TLSA-2005-19 Symlink attack in netpbm may allow arbitrary file overwriting Source: XF Type: UNKNOWN netpbm-temp-insecure-file(14874) Source: XF Type: UNKNOWN netpbm-temp-insecure-file(14874) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:804 Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:810 | ||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: ![]() | ||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||
BACK |