CVE-2003-1366: Infoleak
Published Dec 31, 2003
·Updated
chpass in OpenBSD 2.0 through 3.2 allows local users to read portions of arbitrary files via a hard link attack on a temporary file used to store user database information.
Affected Software
13 affected components
OpenBSD OpenBSD=2.8
OpenBSD OpenBSD=3.1
OpenBSD OpenBSD=2.9
OpenBSD OpenBSD=2.1
OpenBSD OpenBSD=2.2
OpenBSD OpenBSD=2.0
OpenBSD OpenBSD=2.7
OpenBSD OpenBSD=3.2
OpenBSD OpenBSD=2.4
OpenBSD OpenBSD=2.3
OpenBSD OpenBSD=3.0
OpenBSD OpenBSD=2.5
OpenBSD OpenBSD=2.6
Event History
Dec 31, 2003
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityWeaknessAffected Software
Oct 17, 2007
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2003-1366?
CVE-2003-1366 is considered a moderate vulnerability because it allows local users to read arbitrary file contents.
2
How do I fix CVE-2003-1366?
To mitigate CVE-2003-1366, ensure that you apply the latest security patches for OpenBSD and restrict access rights to sensitive files.
3
Which versions of OpenBSD are affected by CVE-2003-1366?
CVE-2003-1366 affects OpenBSD versions from 2.0 through 3.2.
4
What type of attack does CVE-2003-1366 involve?
CVE-2003-1366 involves a hard link attack on a temporary file used by the chpass command.
5
Who is at risk from CVE-2003-1366?
Local users on affected OpenBSD systems are at risk from CVE-2003-1366, as it allows them to exploit the vulnerability.