VulnerabilityModified
CVE-2002-0169
The default stylesheet for DocBook on Red Hat Linux 6.2 through 7.2 is installed with an insecure option enabled, which could allow users to overwrite files outside of the current directory from an untrusted document by using a full pathname as an…
MEDIUM 4.6EPSS 0.41%
Does this matter?
Lower severity and a low EPSS score (0.41%). Track it; it rarely justifies an emergency change on its own.
Description
The default stylesheet for DocBook on Red Hat Linux 6.2 through 7.2 is installed with an insecure option enabled, which could allow users to overwrite files outside of the current directory from an untrusted document by using a full pathname as an element identifier.
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 0.41% probability · 34th percentile
- CISA KEV
- Not listed
- Affected
- redhat/docbook stylesheets · redhat/docbook utils
- Source
- cve@mitre.org
References
- http://online.securityfocus.com/advisories/4095
- http://www.iss.net/security_center/static/8983.php
- http://www.osvdb.org/5349
- http://www.redhat.com/support/errata/RHSA-2002-062.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/4654
- http://online.securityfocus.com/advisories/4095
- http://www.iss.net/security_center/static/8983.php
- http://www.osvdb.org/5349
- http://www.redhat.com/support/errata/RHSA-2002-062.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/4654
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.