4.6
CVSSv2

CVE-2003-0202

Published: 15/04/2004 Updated: 11/07/2017
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The (1) halstead and (2) gather_stats scripts in metrics 1.0 allow local users to overwrite arbitrary files via a symlink attack on temporary files.

Vulnerable Product Search on Vulmon Subscribe to Product

brian renaud metrics 1.0

Vendor Advisories

Paul Szabo and Matt Zimmerman discovered two similar problems in metrics, a tools for software metrics Two scripts in this package, "halstead" and "gather_stats", open temporary files without taking appropriate security precautions "halstead" is installed as a user program, while "gather_stats" is only used in an auxiliary script included in the ...