4.6
CVSSv2

CVE-2003-0539

Published: 18/08/2003 Updated: 11/10/2017
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

skk (Simple Kana to Kanji conversion program) 12.1 and previous versions, and the ddskk package which is based on skk, creates temporary files insecurely, which allows local users to overwrite arbitrary files.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat daredevil skk 11.3.2

redhat daredevil skk 11.3.5

skk skk 10.62a

redhat daredevil skk 11.6.0-10

redhat daredevil skk 11.6.0-6

ddskk ddskk 11.6_.rel.0

redhat ddskk-xemacs 11.6.0-6

redhat ddskk-xemacs 11.6.0-8

redhat daredevil skk 11.6.0-8

redhat ddskk-xemacs 11.6.0-10

Vendor Advisories

skk (Simple Kana to Kanji conversion program), does not take appropriate security precautions when creating temporary files This bug could potentially be exploited to overwrite arbitrary files with the privileges of the user running Emacs and skk ddskk is derived from the same code, and contains the same bug For the stable distribution (woody) t ...