CVE-2002-0169
Summary
| CVE | CVE-2002-0169 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2002-05-29 04:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | The default stylesheet for DocBook on Red Hat Linux 6.2 through 7.2 is installed with an insecure option enabled, which could allow users to overwrite files outside of the current directory from an untrusted document by using a full pathname as an element identifier. |
Risk And Classification
Primary CVSS: v2.0 4.6 from [email protected]
AV:L/AC:L/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:L/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Redhat | Docbook Stylesheets | 1.54.13 | All | All | All |
| Application | Redhat | Docbook Utils | 0.6.13 | All | All | All |
| Application | Redhat | Docbook Utils | 0.6.9-2 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityFocus HOME Advisories: Security vulnerability in DocBooks package | af854a3a-2127-422b-91ae-364da2661108 | online.securityfocus.com | |
| redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | Patch, Vendor Advisory |
| ISS X-Force Database: linux-docbook-stylesheet-insecure (8983): Red Hat Linux DocBook default stylesheet insecure option enabled | af854a3a-2127-422b-91ae-364da2661108 | www.iss.net | |
| www.osvdb.org/5349 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| RedHat DocBook Tools Default Stylesheet Arbitrary File Write Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.