CVE-2004-0974

6 documents6 sources
Severity
2.1LOW
EPSS
0.1%
top 71.74%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 9
Latest updateApr 29

Description

The netatalk package in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users to overwrite files via a symlink attack on temporary files.

CVSS vector

AV:L/AC:L/C:N/I:P/A:NExploitability: 3.9 | Impact: 2.9

Affected Packages5 packages

Debiannetatalk< 1.6.4a-1+2
NVDmandrakesoft/mandrake_linux10.0, 10.1, 9.2+2
NVDredhat/fedora_corecore_2.0, core_3.0+1

Patches

🔴Vulnerability Details

3
GHSA
GHSA-9c82-ch3h-p2hf: The netatalk package in Trustix Secure Linux 12022-04-29
OSV
CVE-2004-0974: The netatalk package in Trustix Secure Linux 12005-02-09
CVEList
CVE-2004-0974: The netatalk package in Trustix Secure Linux 12004-10-20

📋Vendor Advisories

1
Debian
CVE-2004-0974: netatalk - The netatalk package in Trustix Secure Linux 1.5 through 2.1, and possibly other...2004

💬Community

1
Bugzilla
CAN-2004-0974 Netatalk "etc2ps.sh" Script Insecure Temporary File Creation2004-11-09