search menu icon-carat-right cmu-wordmark

CERT Coordination Center

Multiple tools within the Netpbm package create temporary files in an insecure manner

Vulnerability Note VU#487102

Original Release Date: 2004-01-19 | Last Revised: 2004-01-23

Overview

Multiple tools within the Netpbm package create temporary files in an insecure manner.

Description

Netpbm is a toolkit that contains over 220 separate tools for manipulating graphic images. Multiple tools within the Netpbm package create temporary files insecurely.

Impact

A local attacker could overwrite arbitrary files with the privileges of the Netpbm tool process.

Solution

Upgrade or Apply Patch

Upgrade or apply patch as specified by your vendor.

Vendor Information

487102
 

CVSS Metrics

Group Score Vector
Base
Temporal
Environmental

References

Acknowledgements

Thanks to Debian for the information contained in their security advisory.

This document was written by Damon Morda.

Other Information

CVE IDs: CVE-2003-0924
Severity Metric: 2.03
Date Public: 2004-01-18
Date First Published: 2004-01-19
Date Last Updated: 2004-01-23 21:52 UTC
Document Revision: 11

Sponsored by CISA.