CVE-2003-0193: Low severity catdoc catdoc vulnerability
Published Jun 3, 2004
·Updated
msxlsview.sh in xlsview for catdoc 0.91 and earlier allows local users to overwrite arbitrary files via a symlink attack on predictable temporary file names ("word$$.html").
Affected Software
1 affected component
catdoc catdoc<=0.91
Event History
Jun 3, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2003-0193?
CVE-2003-0193 is classified as a medium severity vulnerability due to its potential for local file overwriting.
2
How do I fix CVE-2003-0193?
To fix CVE-2003-0193, upgrade to CatDoc version 0.92 or later to eliminate the symlink vulnerability.
3
What is a symlink attack in the context of CVE-2003-0193?
A symlink attack in CVE-2003-0193 allows attackers to create symbolic links to overwrite arbitrary files by exploiting predictable temporary file names.
4
Who is affected by CVE-2003-0193?
Local users of CatDoc version 0.91 and earlier are affected by CVE-2003-0193.
5
What software is vulnerable to CVE-2003-0193?
CVE-2003-0193 affects CatDoc, specifically versions up to and including 0.91.