Symlink Vulnerability in GNU Enscript Allows File Overwrite by Local Users
CVE-2002-0044

Currently unrated

Key Information:

Vendor
Gnu
Status
Vendor
CVE Published:
31 January 2002

Summary

GNU Enscript versions 1.6.1 and earlier are susceptible to a file overwrite vulnerability, allowing local users to exploit temporary files through a symlink attack. This security issue arises from improper handling of temporary file creation, which can result in unauthorized access to overwrite or manipulate system files, potentially compromising the integrity and security of the affected system. Local users can create a symbolic link pointing to sensitive system files, leading to data loss and security breaches.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.