Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2003-0844

Опубликовано: 17 нояб. 2003
Источник: debian
EPSS Низкий

Описание

mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode without the Apache log, allows local users to overwrite arbitrary files via (1) a symlink attack on predictable temporary filenames on Unix systems, or (2) an NTFS hard link on Windows systems when the "Strengthen default permissions of internal system objects" policy is not enabled.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libapache-mod-gzipunfixedpackage

Примечания

  • Debian doesn't enable vulnerable debug mode.

EPSS

Процентиль: 26%
0.00086
Низкий

Связанные уязвимости

CVSS3: 7.1
nvd
почти 22 года назад

mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode without the Apache log, allows local users to overwrite arbitrary files via (1) a symlink attack on predictable temporary filenames on Unix systems, or (2) an NTFS hard link on Windows systems when the "Strengthen default permissions of internal system objects" policy is not enabled.

CVSS3: 7.1
github
больше 3 лет назад

mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode without the Apache log, allows local users to overwrite arbitrary files via (1) a symlink attack on predictable temporary filenames on Unix systems, or (2) an NTFS hard link on Windows systems when the "Strengthen default permissions of internal system objects" policy is not enabled.

EPSS

Процентиль: 26%
0.00086
Низкий