3.6
CVSSv2

CVE-2002-0044

Published: 31/01/2002 Updated: 10/10/2017
CVSS v2 Base Score: 3.6 | Impact Score: 4.9 | Exploitability Score: 3.9
VMScore: 320
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

GNU Enscript 1.6.1 and previous versions allows local users to overwrite arbitrary files of the Enscript user via a symlink attack on temporary files.

Vulnerable Product Search on Vulmon Subscribe to Product

gnu enscript

redhat linux 6.0

redhat linux 6.1

redhat linux 6.2

redhat linux 7.0

debian debian linux 2.2

redhat linux 7.1

redhat linux 7.2

Vendor Advisories

The version of enscript (a tool to convert ASCII text to different formats) in potato has been found to create temporary files insecurely This has been fixed in version 162-41 ...