First published: Thu Jul 10 2003(Updated: )
skk (Simple Kana to Kanji conversion program) 12.1 and earlier, and the ddskk package which is based on skk, creates temporary files insecurely, which allows local users to overwrite arbitrary files.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Daredevil Skk | =11.6.0-8 | |
Redhat Ddskk-xemacs | =11.6.0-10 | |
Redhat Daredevil Skk | =11.6.0-6 | |
Redhat Ddskk-xemacs | =11.6.0-6 | |
Ddskk | =11.6_.rel.0 | |
Redhat Ddskk-xemacs | =11.6.0-8 | |
Redhat Daredevil Skk | =11.6.0-10 | |
Skk | =10.62a | |
Redhat Daredevil Skk | =11.3.5 | |
Redhat Daredevil Skk | =11.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0539 is considered a moderate severity vulnerability due to its potential to allow local users to overwrite arbitrary files.
To fix CVE-2003-0539, ensure that the software is updated to a version that securely handles temporary files.
CVE-2003-0539 affects skk versions 12.1 and earlier, as well as various versions of the ddskk package.
CVE-2003-0539 cannot be exploited remotely as it requires local user access to the affected system.
The implications of CVE-2003-0539 for system security include the risk of unauthorized file modifications by local users.