CVE-2004-0372: Low severity xine xine vulnerability
Published Mar 27, 2004
·Updated
xine allows local users to overwrite arbitrary files via a symlink attack on a bug report email that is generated by the (1) xine-bugreport or (2) xine-check scripts.
Affected Software
19 affected components
xine xine=1_beta9
xine xine=1_beta3
xine xine=1_rc0a
xine xine=1_beta4
xine xine=1_rc3b
xine xine=1_beta2
xine xine=1_rc3a
xine xine=1_rc2
xine xine=1_beta10
xine xine=1_beta12
xine xine=1_beta11
xine xine=1_beta7
xine xine=1_beta8
xine xine=0.9.13
xine xine=1_rc1
xine xine=1_beta6
xine xine=1_beta1
xine xine=1_rc3
xine xine=1_beta5
Remediation
Patch Available
Event History
Mar 27, 2004
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0372?
CVE-2004-0372 is considered a moderate severity vulnerability due to the potential for local users to overwrite arbitrary files.
2
How can I fix CVE-2004-0372?
To fix CVE-2004-0372, users should upgrade to a patched version of the xine media player that addresses this vulnerability.
3
What types of systems are affected by CVE-2004-0372?
CVE-2004-0372 affects various versions of xine, specifically versions from 0.9.13 to 1_beta12.
4
What is the cause of CVE-2004-0372?
CVE-2004-0372 is caused by a symlink attack that allows local users to exploit bug report emails generated by xine scripts.
5
Is CVE-2004-0372 a remote or local vulnerability?
CVE-2004-0372 is a local vulnerability, meaning it can only be exploited by users with local access to the system.