PT-2004-1087 · Netpbm · Netpbm
Matt Zimmerman
·
Published
2004-02-05
·
Updated
2017-10-10
·
CVE-2003-0924
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
netpbm versions 9.25 and earlier
netpbm versions prior to 9.12-r4
Description
The issue affects the netpbm package, allowing for potential disruption of confidentiality, integrity, and availability of protected information. Exploitation can be carried out remotely or locally, depending on the specific vulnerability. The problem is related to the improper creation of temporary files, which can enable local users to overwrite arbitrary files.
Recommendations
For netpbm versions 9.25 and earlier, update to a version later than 9.25 to resolve the issue.
For netpbm versions prior to 9.12-r4, update to a version later than 9.12-r4 to resolve the issue.
As a temporary workaround, consider restricting access to the netpbm package to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Netpbm