Bugzilla – Bug 64543
VUL-0: CVE-2003-0924: netpbm: insecure tmp file handling
Last modified: 2021-10-27 15:38:37 UTC
Hi, Connectiva released updates for an old bug. " DESCRIPTION netpbm[1] are tools for manipulating graphic files in many formats. Utilities provided by the netpbm package prior to the 9.25 version contain defects[2] in temporary file handling. They create temporary files with predictable names without checking if the target file already exists. SOLUTION It is recommended that all netpbm users upgrade their packages. REFERENCES 1.http://netpbm.sourceforge.net/ 2.http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0924 " CVE-2003-0924 I did not found a hint in bugzilla if we fixed it or not.
<!-- SBZ_reproduce --> -
We have it fixed. *** This bug has been marked as a duplicate of 49036 ***
CVE-2003-0924: CVSS v2 Base Score: 3.7 (AV:L/AC:H/Au:N/C:P/I:P/A:P)