Bugzilla 2.16.x before 2.16.3, 2.17.x before 2.17.4, and earlier versions allows local users to overwrite arbitrary files via a symlink attack on temporary files that are created in directories with group-writable or world-writable permissions.
                
            References
                    | Link | Resource | 
|---|---|
| http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000653 | Vendor Advisory | 
| http://www.bugzilla.org/security/2.16.2/ | |
| http://www.securityfocus.com/bid/7412 | Patch Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
            
            
  | 
    
History
                    No history.
Information
                Published : 2003-08-27 04:00
Updated : 2008-09-05 20:34
NVD link : CVE-2003-0603
Mitre link : CVE-2003-0603
CVE.ORG link : CVE-2003-0603
JSON object : View
Products Affected
                mozilla
- bugzilla
 
CWE
                