First published: Tue Jul 29 2003(Updated: )
Bugzilla 2.16.x before 2.16.3, 2.17.x before 2.17.4, and earlier versions allows local users to overwrite arbitrary files via a symlink attack on temporary files that are created in directories with group-writable or world-writable permissions.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Bugzilla | =2.16.1 | |
Mozilla Bugzilla | =2.16.2 | |
Mozilla Bugzilla | =2.10 | |
Mozilla Bugzilla | =2.17.1 | |
Mozilla Bugzilla | =2.16 | |
Mozilla Bugzilla | =2.14.2 | |
Mozilla Bugzilla | =2.14.3 | |
Mozilla Bugzilla | =2.14.4 | |
Mozilla Bugzilla | =2.17.3 | |
Mozilla Bugzilla | =2.14.5 | |
Mozilla Bugzilla | =2.12 | |
Mozilla Bugzilla | =2.14 | |
Mozilla Bugzilla | =2.14.1 | |
Mozilla Bugzilla | =2.17 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0603 is considered a moderate severity vulnerability due to its potential for local file manipulation.
To fix CVE-2003-0603, update Bugzilla to version 2.16.3 or 2.17.4 or later.
CVE-2003-0603 affects Bugzilla versions up to 2.16.2 and 2.17.x before 2.17.4.
No, CVE-2003-0603 can only be exploited by local users with appropriate access.
The implications of CVE-2003-0603 include the risk of unauthorized overwriting of files on affected systems.