Vulnerabilities > CVE-2003-0193 - Local Insecure Temporary File Creation vulnerability in CatDoc XLSView

047910
CVSS 2.1 - LOW
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
local
low complexity
catdoc
nessus

Summary

msxlsview.sh in xlsview for catdoc 0.91 and earlier allows local users to overwrite arbitrary files via a symlink attack on predictable temporary file names ("word$$.html").

Vulnerable Configurations

Part Description Count
Application
Catdoc
1

Nessus

NASL familyDebian Local Security Checks
NASL idDEBIAN_DSA-575.NASL
descriptionA temporary file problem has been discovered in xlsview from the catdoc suite, convertors from Word to TeX and plain text, which could lead to local users being able to overwrite arbitrary files via a symlink attack on predictable temporary file names.
last seen2020-06-01
modified2020-06-02
plugin id15673
published2004-11-10
reporterThis script is Copyright (C) 2004-2019 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/15673
titleDebian DSA-575-1 : catdoc - insecure temporary file