uulib/uunconc.c in UUDeview 0.5.20, as used in nzbget before 0.3.0 and possibly other products, allows local users to overwrite arbitrary files via a symlink attack on a temporary filename generated by the tempnam function. NOTE: this may be a CVE-2004-2265 regression.
2008-05-16T12:54:00.000
2025-04-09T00:30:58.490
Deferred
CVSSv2: 4.4 (MEDIUM)
AV:L/AC:M/Au:N/C:P/I:P/A:P
3.4
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | nzbget | nzbget | ≤ 0.2.2 | Yes |
Application | nzbget | nzbget | 0.1.0a | Yes |
Application | nzbget | nzbget | 0.1.1 | Yes |
Application | nzbget | nzbget | 0.1.2 | Yes |
Application | nzbget | nzbget | 0.2.0 | Yes |
Application | nzbget | nzbget | 0.2.1 | Yes |
Application | uudeview | uudeview | 0.5.20 | Yes |