First published: Tue Jun 10 2003(Updated: )
znew in the gzip package allows local users to overwrite arbitrary files via a symlink attack on temporary files.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
gzip | <=1.3.5 | |
Debian | =2.2 | |
Debian | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0367 has a medium severity rating due to the potential for local users to overwrite arbitrary files.
To fix CVE-2003-0367, update to a version of GNU gzip newer than 1.3.5 or apply the appropriate patches provided by your distribution.
CVE-2003-0367 affects GNU gzip versions up to and including 1.3.5, as well as Debian Linux versions 2.2 and 3.0.
CVE-2003-0367 describes a symlink attack that allows local users to overwrite temporary files.
No, CVE-2003-0367 is not a remote exploit vulnerability; it requires local access to the affected system.