CVE-2003-0367: Input Validation
Published Jun 10, 2003
·Updated
znew in the gzip package allows local users to overwrite arbitrary files via a symlink attack on temporary files.
Affected Software
3 affected components
GNU gzip<=1.3.5
Debian Debian Linux=2.2
Debian Debian Linux=3.0
Remediation
Patch Available
Patch Available
Event History
Jun 10, 2003
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Jul 2, 2003
Data Sourced
via NVD·04:00 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2003-0367?
CVE-2003-0367 has a medium severity rating due to the potential for local users to overwrite arbitrary files.
2
How do I fix CVE-2003-0367?
To fix CVE-2003-0367, update to a version of GNU gzip newer than 1.3.5 or apply the appropriate patches provided by your distribution.
3
What systems are affected by CVE-2003-0367?
CVE-2003-0367 affects GNU gzip versions up to and including 1.3.5, as well as Debian Linux versions 2.2 and 3.0.
4
What type of attack is described in CVE-2003-0367?
CVE-2003-0367 describes a symlink attack that allows local users to overwrite temporary files.
5
Is CVE-2003-0367 a remote exploit vulnerability?
No, CVE-2003-0367 is not a remote exploit vulnerability; it requires local access to the affected system.