PT-2003-2534 · Debian · Xemacs+4

Published

1970-01-01

·

Updated

2017-10-11

·

CVE-2003-0539

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions skk versions 12.1 and earlier ddskk package versions prior to the fixed version
Description The issue concerns multiple vulnerabilities in the skkserv package of the Debian GNU/Linux operating system and the ddskk package, which can lead to breaches of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited by a local attacker, allowing them to overwrite arbitrary files due to insecure creation of temporary files.
Recommendations For skk versions 12.1 and earlier, update to a version later than 12.1 to resolve the issue. For the ddskk package, restrict access to the package until a fixed version is available, and consider disabling the package as a temporary workaround to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability in the ddskk-xemacs-11.6.0 package, so users of this package should exercise caution and consider alternative measures to protect their systems.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-03489
BDU:2015-03490
BDU:2015-03491
BDU:2015-07789
BDU:2015-07790
CVE-2003-0539
DSA-343

Affected Products

Debian
Xemacs
Ddskk
Ddskk-Xemacs-11.6.0
Skk