CVE-2003-0539
Summary
| CVE | CVE-2003-0539 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2003-08-18 04:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | skk (Simple Kana to Kanji conversion program) 12.1 and earlier, and the ddskk package which is based on skk, creates temporary files insecurely, which allows local users to overwrite arbitrary files. |
Risk And Classification
Primary CVSS: v2.0 4.6 from [email protected]
AV:L/AC:L/Au:N/C:P/I:P/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:L/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ddskk | Ddskk | 11.6_.rel.0 | All | All | All |
| Application | Redhat | Daredevil Skk | 11.3.2 | All | noarch | All |
| Application | Redhat | Daredevil Skk | 11.3.5 | All | noarch | All |
| Application | Redhat | Daredevil Skk | 11.6.0-10 | All | noarch | All |
| Application | Redhat | Daredevil Skk | 11.6.0-6 | All | noarch | All |
| Application | Redhat | Daredevil Skk | 11.6.0-8 | All | noarch | All |
| Application | Redhat | Ddskk-xemacs | 11.6.0-10 | All | noarch | All |
| Application | Redhat | Ddskk-xemacs | 11.6.0-6 | All | noarch | All |
| Application | Redhat | Ddskk-xemacs | 11.6.0-8 | All | noarch | All |
| Application | Skk | Skk | 10.62a | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Debian -- Security Information -- DSA-343-1 skk, ddskk | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.