First published: Wed Dec 31 2003(Updated: )
ez-ipupdate 3.0.11b7 and earlier creates insecure temporary cache files, which allows local users to conduct unauthorized operations via a symlink attack on the ez-ipupdate.cache file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
EZ-IPUpdate by Angus Mackay | =3.0.11b7 | |
EZ-IPUpdate by Angus Mackay | =3.0.11b5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0887 has a medium severity rating due to its potential for local users to conduct unauthorized operations.
Fix CVE-2003-0887 by updating to a version of ez-ipupdate that is 3.0.11b8 or later which addresses the symlink vulnerability.
The vulnerability in CVE-2003-0887 is caused by ez-ipupdate creating insecure temporary cache files that are susceptible to symlink attacks.
CVE-2003-0887 affects users of ez-ipupdate version 3.0.11b7 and earlier on systems where local users have access.
Symlink attacks in the context of CVE-2003-0887 involve malicious local users creating symbolic links to exploit vulnerabilities in the handling of temporary files.