{"api_version":"1","generated_at":"2026-07-23T08:33:08+00:00","cve":"CVE-2002-0169","urls":{"html":"https://cve.report/CVE-2002-0169","api":"https://cve.report/api/cve/CVE-2002-0169.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2002-0169","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2002-0169"},"summary":{"title":"CVE-2002-0169","description":"The default stylesheet for DocBook on Red Hat Linux 6.2 through 7.2 is installed with an insecure option enabled, which could allow users to overwrite files outside of the current directory from an untrusted document by using a full pathname as an element identifier.","state":"PUBLISHED","assigner":"mitre","published_at":"2002-05-29 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.6","severity":"","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:P","baseScore":4.6,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://online.securityfocus.com/advisories/4095","name":"http://online.securityfocus.com/advisories/4095","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus HOME Advisories: Security vulnerability in DocBooks package","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.redhat.com/support/errata/RHSA-2002-062.html","name":"http://www.redhat.com/support/errata/RHSA-2002-062.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"redhat.com | Red Hat Support","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.iss.net/security_center/static/8983.php","name":"http://www.iss.net/security_center/static/8983.php","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"ISS X-Force Database: linux-docbook-stylesheet-insecure (8983): Red Hat Linux DocBook default stylesheet insecure option enabled","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.osvdb.org/5349","name":"http://www.osvdb.org/5349","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.securityfocus.com/bid/4654","name":"http://www.securityfocus.com/bid/4654","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"RedHat DocBook Tools Default Stylesheet Arbitrary File Write Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2002-0169","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2002-0169","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2002","cve_id":"169","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"redhat","cpe5":"docbook_stylesheets","cpe6":"1.54.13","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"169","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"redhat","cpe5":"docbook_utils","cpe6":"0.6.13","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2002","cve_id":"169","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"redhat","cpe5":"docbook_utils","cpe6":"0.6.9-2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T02:42:27.917Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"4654","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/4654"},{"name":"linux-docbook-stylesheet-insecure(8983)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"http://www.iss.net/security_center/static/8983.php"},{"name":"RHSA-2002:062","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://www.redhat.com/support/errata/RHSA-2002-062.html"},{"name":"5349","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/5349"},{"name":"HPSBTL0205-038","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://online.securityfocus.com/advisories/4095"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2002-05-01T00:00:00.000Z","descriptions":[{"lang":"en","value":"The default stylesheet for DocBook on Red Hat Linux 6.2 through 7.2 is installed with an insecure option enabled, which could allow users to overwrite files outside of the current directory from an untrusted document by using a full pathname as an element identifier."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2002-08-17T00:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"4654","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/4654"},{"name":"linux-docbook-stylesheet-insecure(8983)","tags":["vdb-entry","x_refsource_XF"],"url":"http://www.iss.net/security_center/static/8983.php"},{"name":"RHSA-2002:062","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://www.redhat.com/support/errata/RHSA-2002-062.html"},{"name":"5349","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/5349"},{"name":"HPSBTL0205-038","tags":["vendor-advisory","x_refsource_HP"],"url":"http://online.securityfocus.com/advisories/4095"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2002-0169","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The default stylesheet for DocBook on Red Hat Linux 6.2 through 7.2 is installed with an insecure option enabled, which could allow users to overwrite files outside of the current directory from an untrusted document by using a full pathname as an element identifier."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"4654","refsource":"BID","url":"http://www.securityfocus.com/bid/4654"},{"name":"linux-docbook-stylesheet-insecure(8983)","refsource":"XF","url":"http://www.iss.net/security_center/static/8983.php"},{"name":"RHSA-2002:062","refsource":"REDHAT","url":"http://www.redhat.com/support/errata/RHSA-2002-062.html"},{"name":"5349","refsource":"OSVDB","url":"http://www.osvdb.org/5349"},{"name":"HPSBTL0205-038","refsource":"HP","url":"http://online.securityfocus.com/advisories/4095"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2002-0169","datePublished":"2003-04-02T05:00:00.000Z","dateReserved":"2002-04-11T00:00:00.000Z","dateUpdated":"2024-08-08T02:42:27.917Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2002-05-29 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:P","baseScore":4.6,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":3.9,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:docbook_stylesheets:1.54.13:*:*:*:*:*:*:*","matchCriteriaId":"7FB39657-9421-419D-9F23-7719CD834D78"},{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:docbook_utils:0.6.9-2:*:*:*:*:*:*:*","matchCriteriaId":"4966560B-32E1-416E-8A56-53D4A9991155"},{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:docbook_utils:0.6.13:*:*:*:*:*:*:*","matchCriteriaId":"DAAC8103-B804-4520-8AF8-67A333E50497"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2002","CveId":"169","Ordinal":"1","Title":"CVE-2002-0169","CVE":"CVE-2002-0169","Year":"2002"},"notes":[{"CveYear":"2002","CveId":"169","Ordinal":"1","NoteData":"The default stylesheet for DocBook on Red Hat Linux 6.2 through 7.2 is installed with an insecure option enabled, which could allow users to overwrite files outside of the current directory from an untrusted document by using a full pathname as an element identifier.","Type":"Description","Title":"CVE-2002-0169"},{"CveYear":"2002","CveId":"169","Ordinal":"2","NoteData":"2003-04-02","Type":"Other","Title":"Published"},{"CveYear":"2002","CveId":"169","Ordinal":"3","NoteData":"2002-08-16","Type":"Other","Title":"Modified"}]}}}