ID

VAR-200311-0047


CVE

CVE-2003-0875


TITLE

OpenSLP slpd script slpd.all_init Symbolic link vulnerability

Trust: 0.6

sources: CNNVD: CNNVD-200311-078

DESCRIPTION

Symbolic link vulnerability in the slpd script slpd.all_init for OpenSLP before 1.0.11 allows local users to overwrite arbitrary files via the route.check temporary file

Trust: 1.26

sources: NVD: CVE-2003-0875 // BID: 87721 // VULHUB: VHN-7700

AFFECTED PRODUCTS

vendor:openslpmodel:openslpscope:lteversion:1.0.11

Trust: 1.0

vendor:openslpmodel:openslpscope:eqversion:1.0.11

Trust: 0.9

sources: BID: 87721 // CNNVD: CNNVD-200311-078 // NVD: CVE-2003-0875

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2003-0875
value: LOW

Trust: 1.0

CNNVD: CNNVD-200311-078
value: LOW

Trust: 0.6

VULHUB: VHN-7700
value: LOW

Trust: 0.1

nvd@nist.gov: CVE-2003-0875
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:N/I:P/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

VULHUB: VHN-7700
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:N/I:P/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-7700 // CNNVD: CNNVD-200311-078 // NVD: CVE-2003-0875

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2003-0875

THREAT TYPE

local

Trust: 0.9

sources: BID: 87721 // CNNVD: CNNVD-200311-078

TYPE

unknown

Trust: 0.6

sources: CNNVD: CNNVD-200311-078

EXTERNAL IDS

db:NVDid:CVE-2003-0875

Trust: 2.0

db:CNNVDid:CNNVD-200311-078

Trust: 0.7

db:BUGTRAQid:20030818 OPENSLP INITSCRIPT SYMLINK VULNERABILITY

Trust: 0.6

db:CONECTIVAid:CLA-2003:723

Trust: 0.6

db:BIDid:87721

Trust: 0.4

db:VULHUBid:VHN-7700

Trust: 0.1

sources: VULHUB: VHN-7700 // BID: 87721 // CNNVD: CNNVD-200311-078 // NVD: CVE-2003-0875

REFERENCES

url:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000723

Trust: 1.9

url:http://marc.info/?l=bugtraq&m=106123103606336&w=2

Trust: 1.0

url:http://marc.theaimsgroup.com/?l=bugtraq&m=106123103606336&w=2

Trust: 0.9

url:http://marc.info/?l=bugtraq&m=106123103606336&w=2

Trust: 0.1

url:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000723

Trust: 0.1

sources: VULHUB: VHN-7700 // BID: 87721 // CNNVD: CNNVD-200311-078 // NVD: CVE-2003-0875

CREDITS

Unknown

Trust: 0.3

sources: BID: 87721

SOURCES

db:VULHUBid:VHN-7700
db:BIDid:87721
db:CNNVDid:CNNVD-200311-078
db:NVDid:CVE-2003-0875

LAST UPDATE DATE

2024-08-14T15:20:18.574000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-7700date:2016-10-18T00:00:00
db:BIDid:87721date:2003-11-17T00:00:00
db:CNNVDid:CNNVD-200311-078date:2005-10-20T00:00:00
db:NVDid:CVE-2003-0875date:2016-10-18T02:38:09.843

SOURCES RELEASE DATE

db:VULHUBid:VHN-7700date:2003-11-17T00:00:00
db:BIDid:87721date:2003-11-17T00:00:00
db:CNNVDid:CNNVD-200311-078date:2003-11-17T00:00:00
db:NVDid:CVE-2003-0875date:2003-11-17T05:00:00