VulnerabilityModified
CVE-2003-0924
netpbm 9.25 and earlier does not properly create temporary files, which allows local users to overwrite arbitrary files.
LOW 3.7EPSS 0.41%
Does this matter?
Lower severity and a low EPSS score (0.41%). Track it; it rarely justifies an emergency change on its own.
Description
netpbm 9.25 and earlier does not properly create temporary files, which allows local users to overwrite arbitrary files.
- CVSS 2.0
- 3.7 LOWAV:L/AC:H/Au:N/C:P/I:P/A:P
- EPSS
- 0.41% probability · 35th percentile
- CISA KEV
- Not listed
- Affected
- netpbm/netpbm
- Source
- cve@mitre.org
References
- ftp://patches.sgi.com/support/free/security/advisories/20040201-01-U.asc
- http://www.debian.org/security/2004/dsa-426Patch, Vendor Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200410-02.xml
- http://www.kb.cert.org/vuls/id/487102Third Party Advisory, US Government Resource
- http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:011
- http://www.redhat.com/support/errata/RHSA-2004-030.htmlPatch, Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2004-031.html
- http://www.securityfocus.com/bid/9442Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/14874
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A804
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A810
- ftp://patches.sgi.com/support/free/security/advisories/20040201-01-U.asc
- http://www.debian.org/security/2004/dsa-426Patch, Vendor Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200410-02.xml
- http://www.kb.cert.org/vuls/id/487102Third Party Advisory, US Government Resource
- http://www.mandrakesoft.com/security/advisories?name=MDKSA-2004:011
- http://www.redhat.com/support/errata/RHSA-2004-030.htmlPatch, Vendor Advisory
- http://www.redhat.com/support/errata/RHSA-2004-031.html
- http://www.securityfocus.com/bid/9442Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/14874
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A804
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A810
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.