CVE-2004-0372
xine-ui - insecure temporary file creation
EPSS 0.34%
描述
xine allows local users to overwrite arbitrary files via a symlink attack on a bug report email that is generated by the (1) xine-bugreport or (2) xine-check scripts.
如何修補 CVE-2004-0372
要修補 CVE-2004-0372,請將受影響套件升級到下列已修補版本。
- Debian/xine-ui—升級至 0.99.1-1 或更新版本
- Debian/xine-ui—升級至 0.9.8-5 或更新版本
CVE-2004-0372 正在被利用嗎?
低 — EPSS 為 0.3%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- from 0, < 0.99.1-1
- from 0, < 0.9.8-5