CVE-2003-0193

msxlsview.sh in xlsview for catdoc 0.91 and earlier allows local users to overwrite arbitrary files via a symlink attack on predictable temporary file names ("word$$.html").
Configurations

Configuration 1 (hide)

cpe:2.3:a:catdoc:catdoc:*:*:*:*:*:*:*:*

History

20 Nov 2024, 23:44

Type Values Removed Values Added
References () http://bugs.debian.org/cgi-bin/bugreport.cgi?archive=no&bug=183525 - () http://bugs.debian.org/cgi-bin/bugreport.cgi?archive=no&bug=183525 -
References () http://secunia.com/advisories/13021/ - () http://secunia.com/advisories/13021/ -
References () http://secunia.com/advisories/13022/ - () http://secunia.com/advisories/13022/ -
References () http://www.debian.org/security/2004/dsa-575 - () http://www.debian.org/security/2004/dsa-575 -
References () http://www.osvdb.org/11193 - () http://www.osvdb.org/11193 -
References () http://www.securityfocus.com/bid/11560 - () http://www.securityfocus.com/bid/11560 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/16335 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/16335 -

Information

Published : 2004-08-18 04:00

Updated : 2024-11-20 23:44


NVD link : CVE-2003-0193

Mitre link : CVE-2003-0193

CVE.ORG link : CVE-2003-0193


JSON object : View

Products Affected

catdoc

  • catdoc