Symlink Vulnerability in GNU Enscript Allows File Overwrite by Local Users
CVE-2002-0044
Currently unrated
Summary
GNU Enscript versions 1.6.1 and earlier are susceptible to a file overwrite vulnerability, allowing local users to exploit temporary files through a symlink attack. This security issue arises from improper handling of temporary file creation, which can result in unauthorized access to overwrite or manipulate system files, potentially compromising the integrity and security of the affected system. Local users can create a symbolic link pointing to sensitive system files, leading to data loss and security breaches.
References
Timeline
Vulnerability published
Vulnerability Reserved