Vulnerability Description
chpass in OpenBSD 2.0 through 3.2 allows local users to read portions of arbitrary files via a hard link attack on a temporary file used to store user database information.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openbsd | Openbsd | 2.0 |
Related Weaknesses (CWE)
References
- http://securityreason.com/securityalert/3238
- http://www.epita.fr/~bevand_m/asa/asa-0001
- http://www.securityfocus.com/archive/1/309962
- http://www.securityfocus.com/bid/6748
- http://www.securitytracker.com/id?1006035
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11233
- http://securityreason.com/securityalert/3238
- http://www.epita.fr/~bevand_m/asa/asa-0001
- http://www.securityfocus.com/archive/1/309962
- http://www.securityfocus.com/bid/6748
- http://www.securitytracker.com/id?1006035
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11233
FAQ
What is CVE-2003-1366?
CVE-2003-1366 is a vulnerability with a CVSS score of 3.3 (LOW). chpass in OpenBSD 2.0 through 3.2 allows local users to read portions of arbitrary files via a hard link attack on a temporary file used to store user database information.
How severe is CVE-2003-1366?
CVE-2003-1366 has been rated LOW with a CVSS base score of 3.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2003-1366?
Check the references section above for vendor advisories and patch information. Affected products include: Openbsd Openbsd.