CVE-2004-0966
published 2005-02-09CVE-2004-0966: The (1) autopoint and (2) gettextize scripts in the GNU gettext package 1.14 and later versions, as used in Trustix Secure Linux 1.5 through 2.1 and other…
PriorityP46low2.1CVSS 2.0
AVLACLAuNCNIPAN
EPSS
0.40%
32.6th percentile
The (1) autopoint and (2) gettextize scripts in the GNU gettext package 1.14 and later versions, as used in Trustix Secure Linux 1.5 through 2.1 and other operating systems, allows local users to overwrite files via a symlink attack on temporary files.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gettext | < gettext 0.14.1-6 (bookworm) | gettext 0.14.1-6 (bookworm) |
| gnu | gettext | — | — |
| gnu | gettext | >= 0 < 0.14.1-6 | 0.14.1-6 |
| gnu | gettext | >= 0 < 0.14.1-6 | 0.14.1-6 |
| gnu | gettext | >= 0 < 0.14.1-6 | 0.14.1-6 |
| gnu | gettext | >= 0 < 0.14.1-6 | 0.14.1-6 |
| ubuntu | ubuntu_linux | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
osv2.1LOW
vendor_debian2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
gettext vulnerabilities
vendor_ubuntu·2004-10-27
CVE-2004-0966 gettext vulnerabilities
Title: gettext vulnerabilities
Summary: gettext vulnerabilities
Recently, Trustix Secure Linux discovered some vulnerabilities in the
gettext package. The programs "autopoint" and "gettextize" created
temporary files in an insecure way, which allowed a symlink attack to
create or overwrite arbitrary files with the privileges of the user
invoking the program.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2004-0966: gettext - The (1) autopoint and (2) gettextize scripts in the GNU gettext package 1.14 and...
vendor_debian·2004·CVSS 2.1
CVE-2004-0966 [LOW] CVE-2004-0966: gettext - The (1) autopoint and (2) gettextize scripts in the GNU gettext package 1.14 and...
The (1) autopoint and (2) gettextize scripts in the GNU gettext package 1.14 and later versions, as used in Trustix Secure Linux 1.5 through 2.1 and other operating systems, allows local users to overwrite files via a symlink attack on temporary files.
Scope: local
bookworm: resolved (fixed in 0.14.1-6)
bullseye: resolved (fixed in 0.14.1-6)
forky: resolved (fixed in 0.14.1-6)
sid: resolved (fixed in 0.14.1-6)
trixie: resolved (fixed in 0.14.1-6)
GHSA
GHSA-6w8j-6937-5hm5: The (1) autopoint and (2) gettextize scripts in the GNU gettext package 1
ghsa_unreviewed·2022-04-29
CVE-2004-0966 [LOW] GHSA-6w8j-6937-5hm5: The (1) autopoint and (2) gettextize scripts in the GNU gettext package 1
The (1) autopoint and (2) gettextize scripts in the GNU gettext package 1.14 and later versions, as used in Trustix Secure Linux 1.5 through 2.1 and other operating systems, allows local users to overwrite files via a symlink attack on temporary files.
OSV
CVE-2004-0966: The (1) autopoint and (2) gettextize scripts in the GNU gettext package 1
osv·2005-02-09·CVSS 2.1
CVE-2004-0966 [LOW] CVE-2004-0966: The (1) autopoint and (2) gettextize scripts in the GNU gettext package 1
The (1) autopoint and (2) gettextize scripts in the GNU gettext package 1.14 and later versions, as used in Trustix Secure Linux 1.5 through 2.1 and other operating systems, allows local users to overwrite files via a symlink attack on temporary files.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=136323http://marc.info/?l=bugtraq&m=110382652226638&w=2http://www.gentoo.org/security/en/glsa/glsa-200410-10.xmlhttp://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00000.htmlhttp://www.securityfocus.com/bid/11282http://www.trustix.org/errata/2004/0050http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:051https://exchange.xforce.ibmcloud.com/vulnerabilities/17583https://www.ubuntu.com/usn/usn-5-1/http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=136323http://marc.info/?l=bugtraq&m=110382652226638&w=2http://www.gentoo.org/security/en/glsa/glsa-200410-10.xmlhttp://www.redhat.com/archives/fedora-legacy-announce/2006-January/msg00000.htmlhttp://www.securityfocus.com/bid/11282http://www.trustix.org/errata/2004/0050http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2006:051https://exchange.xforce.ibmcloud.com/vulnerabilities/17583https://www.ubuntu.com/usn/usn-5-1/
2005-02-09
Published