CVE-2004-0372
xine-ui - insecure temporary file creation
EPSS 0.34%
Description
xine allows local users to overwrite arbitrary files via a symlink attack on a bug report email that is generated by the (1) xine-bugreport or (2) xine-check scripts.
How to fix CVE-2004-0372
To remediate CVE-2004-0372, upgrade the affected package to a fixed version below.
- Debian/xine-ui—upgrade to 0.99.1-1 or later
- Debian/xine-ui—upgrade to 0.9.8-5 or later
Is CVE-2004-0372 being exploited?
Low — EPSS is 0.3%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 0.99.1-1
- from 0, < 0.9.8-5