4.6
CVSSv2

CVE-2003-0014

Published: 11/01/2003 Updated: 11/07/2017
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

gsinterf.c in bmv 1.2 and previous versions allows local users to overwrite arbitrary files via a symlink attack on temporary files.

Vulnerable Product Search on Vulmon Subscribe to Product

bmv bmv 1.2

Vendor Advisories

Peter Samuelson, upstream maintainer of bmv, a PostScript viewer for SVGAlib, discovered that temporary files are created in an insecure fashion A malicious local user could cause arbitrary files to be overwritten by a symlink attack For the stable distribution (woody) this problem has been fixed in version 12-142 For the unstable distribution ...