Lucene search

K
cve[email protected]CVE-2003-0547
HistoryAug 27, 2003 - 4:00 a.m.

CVE-2003-0547

2003-08-2704:00:00
web.nvd.nist.gov
27
gdm
cve-2003-0547
security
symlink attack
vulnerability

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

6.2 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%

GDM before 2.4.1.6, when using the “examine session errors” feature, allows local users to read arbitrary files via a symlink attack on the ~/.xsession-errors file.

Affected configurations

NVD
Node
gnomegdmMatch2.4.1
OR
gnomegdmMatch2.4.1.1
OR
gnomegdmMatch2.4.1.2
OR
gnomegdmMatch2.4.1.3
OR
gnomegdmMatch2.4.1.4
OR
gnomegdmMatch2.4.1.5
OR
gnomegdmMatch2.4.1.6
OR
redhatkdebaseMatch2.4.0.7.13i386
OR
redhatkdebaseMatch2.4.1.3.5i386

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

6.2 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

5.1%