Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2003-0603 | First vendor Publication | 2003-08-27 |
Vendor | Cve | Last vendor Modification | 2024-11-20 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:L/AC:L/Au:N/C:N/I:P/A:N) | |||
---|---|---|---|
Cvss Base Score | 2.1 | Attack Range | Local |
Cvss Impact Score | 2.9 | Attack Complexity | Low |
Cvss Expoit Score | 3.9 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Bugzilla 2.16.x before 2.16.3, 2.17.x before 2.17.4, and earlier versions allows local users to overwrite arbitrary files via a symlink attack on temporary files that are created in directories with group-writable or world-writable permissions. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0603 |
CPE : Common Platform Enumeration
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
6385 | Bugzilla checksetup.pl Symlink Arbitrary File Overwrite Bugzilla contains a flaw that may allow a malicious user to overwrite arbitrary files. The problem is that the program creates temporary files in directories with insecure permissions and does not verify that the filename is unused. It is possible that the flaw may allow a malicious user to create a symlink from the checksetup.pl script and overwrite an arbitrary file, resulting in a loss of integrity or availability. |
6384 | Bugzilla defparams.pl Symlink Arbitrary File Overwrite Bugzilla contains a flaw that may allow a malicious user to overwrite arbitrary files. The problem is that the program creates temporary files in directories with insecure permissions and does not verify that the filename is unused. It is possible that the flaw may allow a malicious user to create a symlink from the defparams.pl script and overwrite an arbitrary file, resulting in a loss of integrity or availability. |
6383 | Bugzilla globals.pl Symlink Arbitrary File Overwrite Bugzilla contains a flaw that may allow a malicious user to overwrite arbitrary files. The problem is that the program creates temporary files in directories with insecure permissions and does not verify that the filename is unused. It is possible that the flaw may allow a malicious user to create a symlink from the globals.pl script and overwrite an arbitrary file, resulting in a loss of integrity or availability. |
6348 | Bugzilla showdependencygraph.cgi Symlink Arbitrary File Overwrite Bugzilla contains a flaw that may allow a malicious user to overwrite arbitrary files. The problem is that the program creates temporary files in directories with insecure permissions and does not verify that the filename is unused. It is possible that the flaw may allow a malicious user to create a symlink from the showdependencygraph.cgi script and overwrite an arbitrary file, resulting in a loss of integrity or availability. |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2003-04-26 | Name : The remote web server contains a CGI application that is affected by several ... File : bugzilla_xss_and_tmp_files.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Source | Url |
---|
Alert History
Date | Informations |
---|---|
2024-11-28 23:23:24 |
|
2024-11-28 12:05:40 |
|
2021-05-04 12:02:04 |
|
2021-04-22 01:02:11 |
|
2020-05-23 00:15:27 |
|
2014-02-17 10:26:24 |
|
2013-05-11 11:52:16 |
|