CVE-2002-0044: Low severity GNU Enscript vulnerability
Published Jan 31, 2002
·Updated
GNU Enscript 1.6.1 and earlier allows local users to overwrite arbitrary files of the Enscript user via a symlink attack on temporary files.
Affected Software
8 affected components
GNU Enscript<=1.6.1
Debian Debian Linux=2.2
redhat Linux=7.0
redhat Linux=6.1
redhat Linux=7.2
redhat Linux=6.2
redhat Linux=6.0
redhat Linux=7.1
Event History
Jan 31, 2002
CVE Published
05:00 AM
Jun 25, 2002
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2002-0044?
CVE-2002-0044 is classified as a medium severity vulnerability due to its potential for local users to exploit it via a symlink attack.
2
How do I fix CVE-2002-0044?
To fix CVE-2002-0044, update GNU Enscript to version 1.6.2 or later to mitigate the symlink attack risk.
3
Which software is affected by CVE-2002-0044?
CVE-2002-0044 affects GNU Enscript versions 1.6.1 and earlier, as well as specific versions of Red Hat Linux and Debian.
4
What type of attack does CVE-2002-0044 exploit?
CVE-2002-0044 exploits a symlink vulnerability allowing local users to overwrite arbitrary files.
5
Is CVE-2002-0044 still a concern for current systems?
CVE-2002-0044 is less of a concern for current systems that have been updated since it affects very outdated versions of software.