Vulnerabilities > CVE-2003-0606

047910
CVSS 4.6 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
local
low complexity
cvsup
sup
nessus

Summary

sup 1.8 and earlier does not properly create temporary files, which allows local users to overwrite arbitrary files.

Vulnerable Configurations

Part Description Count
Application
Cvsup
1
Application
Sup
1

Nessus

NASL familyDebian Local Security Checks
NASL idDEBIAN_DSA-353.NASL
descriptionsup, a package used to maintain collections of files in identical versions across machines, fails to take appropriate security precautions when creating temporary files. A local attacker could exploit this vulnerability to overwrite arbitrary files with the privileges of the user running sup.
last seen2020-06-01
modified2020-06-02
plugin id15190
published2004-09-29
reporterThis script is Copyright (C) 2004-2019 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/15190
titleDebian DSA-353-1 : sup - insecure temporary file