CVE-2003-0214 describes a local privilege escalation vulnerability in the run-mailcap utility within mime-support versions 3.22 and earlier, affecting Debian systems. An attacker can exploit this flaw through a symlink attack on temporary files, allowing them to overwrite arbitrary files on the system. With a CVSS score of 4.6 (AV:L/AC:L/Au:N/C:P/I:P/A:P), this vulnerability requires local access and low attack complexity, potentially leading to partial confidentiality, integrity, and availability impacts. There is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB, although it has received a notable amount of community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.9CPE matchmatch criteria | cpe:2.3:a:debian:mime-support:3.9:*:*:*:*:*:*:* | ||
3.10CPE matchmatch criteria | cpe:2.3:a:debian:mime-support:3.10:*:*:*:*:*:*:* | ||
3.11CPE matchmatch criteria | cpe:2.3:a:debian:mime-support:3.11:*:*:*:*:*:*:* | ||
3.12CPE matchmatch criteria | cpe:2.3:a:debian:mime-support:3.12:*:*:*:*:*:*:* | ||
3.13CPE matchmatch criteria | cpe:2.3:a:debian:mime-support:3.13:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.