CVE-2004-0107

9 documents7 sources
Severity
4.6MEDIUM
EPSS
0.1%
top 77.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 15
Latest updateMay 3

Description

The (1) post and (2) trigger scripts in sysstat 4.0.7 and earlier allow local users to overwrite arbitrary files via symlink attacks on temporary files, a different vulnerability than CVE-2004-0108.

CVSS vector

AV:L/AC:L/C:P/I:P/A:PExploitability: 3.9 | Impact: 6.4

Affected Packages4 packages

Debiansysstat< 5.0.2-1+3
NVDredhat/sysstat4.0.7-3
NVDsysstat/sysstat9 versions+8
NVDsgi/propack2.3, 2.4+1

Patches

🔴Vulnerability Details

3
GHSA
GHSA-3hhr-4c49-xc95: The (1) post and (2) trigger scripts in sysstat 42022-05-03
OSV
CVE-2004-0107: The (1) post and (2) trigger scripts in sysstat 42004-04-15
CVEList
CVE-2004-0107: The (1) post and (2) trigger scripts in sysstat 42004-03-16

📋Vendor Advisories

3
Red Hat
security flaw2004-03-10
Red Hat
security flaw2004-03-10
Debian
CVE-2004-0107: sysstat - The (1) post and (2) trigger scripts in sysstat 4.0.7 and earlier allow local us...2004

💬Community

2
Bugzilla
CVE-2004-0107 security flaw2018-08-16
Bugzilla
CVE-2004-0108 security flaw2018-08-16
CVE-2004-0107 (MEDIUM CVSS 4.6) | The (1) post and (2) trigger script | cvebase.io