Vulnerability Description
msxlsview.sh in xlsview for catdoc 0.91 and earlier allows local users to overwrite arbitrary files via a symlink attack on predictable temporary file names ("word$$.html").
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Catdoc | Catdoc | <= 0.91 |
References
- http://bugs.debian.org/cgi-bin/bugreport.cgi?archive=no&bug=183525
- http://secunia.com/advisories/13021/
- http://secunia.com/advisories/13022/
- http://www.debian.org/security/2004/dsa-575
- http://www.osvdb.org/11193
- http://www.securityfocus.com/bid/11560
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16335
- http://bugs.debian.org/cgi-bin/bugreport.cgi?archive=no&bug=183525
- http://secunia.com/advisories/13021/
- http://secunia.com/advisories/13022/
- http://www.debian.org/security/2004/dsa-575
- http://www.osvdb.org/11193
- http://www.securityfocus.com/bid/11560
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16335
FAQ
What is CVE-2003-0193?
CVE-2003-0193 is a vulnerability with a CVSS score of 2.1 (LOW). msxlsview.sh in xlsview for catdoc 0.91 and earlier allows local users to overwrite arbitrary files via a symlink attack on predictable temporary file names ("word$$.html").
How severe is CVE-2003-0193?
CVE-2003-0193 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2003-0193?
Check the references section above for vendor advisories and patch information. Affected products include: Catdoc Catdoc.