CVE-2004-0968
published 2005-02-09CVE-2004-0968: The catchsegv script in glibc 2.3.2 and earlier allows local users to overwrite files via a symlink attack on temporary files.
PriorityP47low2.1CVSS 2.0
AVLACLAuNCNIPAN
EPSS
0.39%
31.6th percentile
The catchsegv script in glibc 2.3.2 and earlier allows local users to overwrite files via a symlink attack on temporary files.
Affected
33 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | glibc | < glibc 2.3.2.ds1-19 (bookworm) | glibc 2.3.2.ds1-19 (bookworm) |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
| gnu | glibc | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
osv2.1LOW
vendor_debian2.1LOW
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Standard C library script vulnerabilities
vendor_ubuntu·2004-10-28
CVE-2004-0968 Standard C library script vulnerabilities
Title: Standard C library script vulnerabilities
Summary: Standard C library script vulnerabilities
Recently, Trustix Secure Linux discovered some vulnerabilities in the
libc6 package. The utilities "catchsegv" and "glibcbug" created
temporary files in an insecure way, which allowed a symlink attack to
create or overwrite arbitrary files with the privileges of the user
invoking the program.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
security flaw
vendor_redhat·2004-10-24·CVSS 2.1
CVE-2004-1382 [LOW] security flaw
security flaw
The glibcbug script in glibc 2.3.4 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files, a different vulnerability than CVE-2004-0968.
Red Hat
security flaw
vendor_redhat·2004-09-30·CVSS 2.1
CVE-2004-0968 [LOW] security flaw
security flaw
The catchsegv script in glibc 2.3.2 and earlier allows local users to overwrite files via a symlink attack on temporary files.
Debian
CVE-2004-1382: glibc - The glibcbug script in glibc 2.3.4 and earlier allows local users to overwrite a...
vendor_debian·2004·CVSS 2.1
CVE-2004-1382 [LOW] CVE-2004-1382: glibc - The glibcbug script in glibc 2.3.4 and earlier allows local users to overwrite a...
The glibcbug script in glibc 2.3.4 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files, a different vulnerability than CVE-2004-0968.
Scope: local
bookworm: resolved (fixed in 2.3.2.ds1-19)
bullseye: resolved (fixed in 2.3.2.ds1-19)
forky: resolved (fixed in 2.3.2.ds1-19)
sid: resolved (fixed in 2.3.2.ds1-19)
trixie: resolved (fixed in 2.3.2.ds1-19)
Debian
CVE-2004-0968: glibc - The catchsegv script in glibc 2.3.2 and earlier allows local users to overwrite ...
vendor_debian·2004·CVSS 2.1
CVE-2004-0968 [LOW] CVE-2004-0968: glibc - The catchsegv script in glibc 2.3.2 and earlier allows local users to overwrite ...
The catchsegv script in glibc 2.3.2 and earlier allows local users to overwrite files via a symlink attack on temporary files.
Scope: local
bookworm: resolved (fixed in 2.3.2.ds1-19)
bullseye: resolved (fixed in 2.3.2.ds1-19)
forky: resolved (fixed in 2.3.2.ds1-19)
sid: resolved (fixed in 2.3.2.ds1-19)
trixie: resolved (fixed in 2.3.2.ds1-19)
GHSA
GHSA-q8m5-35w7-x258: The catchsegv script in glibc 2
ghsa_unreviewed·2022-04-29
CVE-2004-0968 [LOW] GHSA-q8m5-35w7-x258: The catchsegv script in glibc 2
The catchsegv script in glibc 2.3.2 and earlier allows local users to overwrite files via a symlink attack on temporary files.
GHSA
GHSA-rmvw-6cmx-qgfg: The glibcbug script in glibc 2
ghsa_unreviewed·2022-04-29·CVSS 2.1
CVE-2004-1382 [LOW] GHSA-rmvw-6cmx-qgfg: The glibcbug script in glibc 2
The glibcbug script in glibc 2.3.4 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files, a different vulnerability than CVE-2004-0968.
OSV
CVE-2004-0968: The catchsegv script in glibc 2
osv·2005-02-09·CVSS 2.1
CVE-2004-0968 [LOW] CVE-2004-0968: The catchsegv script in glibc 2
The catchsegv script in glibc 2.3.2 and earlier allows local users to overwrite files via a symlink attack on temporary files.
OSV
CVE-2004-1382: The glibcbug script in glibc 2
osv·2004-12-31·CVSS 2.1
CVE-2004-1382 [LOW] CVE-2004-1382: The glibcbug script in glibc 2
The glibcbug script in glibc 2.3.4 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files, a different vulnerability than CVE-2004-0968.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2004-1382 security flaw
bugzilla·2018-08-16·CVSS 2.1
CVE-2004-1382 [LOW] CVE-2004-1382 security flaw
CVE-2004-1382 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
The glibcbug script in glibc 2.3.4 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files, a different vulnerability than CVE-2004-0968.
Bugzilla
CVE-2004-0968 security flaw
bugzilla·2018-08-16·CVSS 2.1
CVE-2004-0968 [LOW] CVE-2004-0968 security flaw
CVE-2004-0968 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
The catchsegv script in glibc 2.3.2 and earlier allows local users to overwrite files via a symlink attack on temporary files.
http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=136318http://security.gentoo.org/glsa/glsa-200410-19.xmlhttp://www.debian.org/security/2005/dsa-636http://www.redhat.com/support/errata/RHSA-2004-586.htmlhttp://www.redhat.com/support/errata/RHSA-2005-261.htmlhttp://www.securityfocus.com/bid/11286http://www.trustix.org/errata/2004/0050https://exchange.xforce.ibmcloud.com/vulnerabilities/17583https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9523https://www.ubuntu.com/usn/usn-4-1/http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=136318http://security.gentoo.org/glsa/glsa-200410-19.xmlhttp://www.debian.org/security/2005/dsa-636http://www.redhat.com/support/errata/RHSA-2004-586.htmlhttp://www.redhat.com/support/errata/RHSA-2005-261.htmlhttp://www.securityfocus.com/bid/11286http://www.trustix.org/errata/2004/0050https://exchange.xforce.ibmcloud.com/vulnerabilities/17583https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9523https://www.ubuntu.com/usn/usn-4-1/
2005-02-09
Published