CVE-2004-0770
published 2005-01-10CVE-2004-0770: romload.c in DGen Emulator 1.23 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files during decompression of (1)…
PriorityP49low2.1CVSS 2.0
AVLACLAuNCNIPAN
EPSS
0.34%
27.0th percentile
romload.c in DGen Emulator 1.23 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files during decompression of (1) gzip or (2) bzip ROM files.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | dgen | < dgen 1.23-6 (bookworm) | dgen 1.23-6 (bookworm) |
| dgen | emulator | — | — |
| dgen | emulator | — | — |
| dgen | emulator | — | — |
| dgen | emulator | — | — |
| dgen | emulator | — | — |
| dgen | emulator | — | — |
| dgen | emulator | — | — |
| dgen | emulator | — | — |
| dgen | emulator | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
osv2.1LOW
vendor_debian2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2004-0770: dgen - romload.c in DGen Emulator 1.23 and earlier allows local users to overwrite arbi...
vendor_debian·2004·CVSS 2.1
CVE-2004-0770 [LOW] CVE-2004-0770: dgen - romload.c in DGen Emulator 1.23 and earlier allows local users to overwrite arbi...
romload.c in DGen Emulator 1.23 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files during decompression of (1) gzip or (2) bzip ROM files.
Scope: local
bookworm: resolved (fixed in 1.23-6)
bullseye: resolved (fixed in 1.23-6)
GHSA
GHSA-xgg4-vjx4-5hxp: romload
ghsa_unreviewed·2022-04-29
CVE-2004-0770 [LOW] GHSA-xgg4-vjx4-5hxp: romload
romload.c in DGen Emulator 1.23 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files during decompression of (1) gzip or (2) bzip ROM files.
OSV
CVE-2004-0770: romload
osv·2005-01-10·CVSS 2.1
CVE-2004-0770 [LOW] CVE-2004-0770: romload
romload.c in DGen Emulator 1.23 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files during decompression of (1) gzip or (2) bzip ROM files.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=263282&archive=yeshttp://secunia.com/advisories/12214http://www.securityfocus.com/bid/10855https://exchange.xforce.ibmcloud.com/vulnerabilities/16884http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=263282&archive=yeshttp://secunia.com/advisories/12214http://www.securityfocus.com/bid/10855https://exchange.xforce.ibmcloud.com/vulnerabilities/16884
2005-01-10
Published