CVE-2004-0975

9 documents8 sources
Severity
2.1LOW
EPSS
0.1%
top 77.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 9
Latest updateApr 29

Description

The der_chop script in the openssl package in Trustix Secure Linux 1.5 through 2.1 and other operating systems allows local users to overwrite files via a symlink attack on temporary files.

CVSS vector

AV:L/AC:L/C:N/I:P/A:NExploitability: 3.9 | Impact: 2.9

Affected Packages5 packages

Patches

🔴Vulnerability Details

3
GHSA
GHSA-53cg-whph-j92f: The der_chop script in the openssl package in Trustix Secure Linux 12022-04-29
OSV
CVE-2004-0975: The der_chop script in the openssl package in Trustix Secure Linux 12005-02-09
CVEList
CVE-2004-0975: The der_chop script in the openssl package in Trustix Secure Linux 12004-10-20

📋Vendor Advisories

3
Ubuntu
openssl script vulnerability2004-11-12
Red Hat
security flaw2004-09-30
Debian
CVE-2004-0975: openssl - The der_chop script in the openssl package in Trustix Secure Linux 1.5 through 2...2004

💬Community

1
Bugzilla
CVE-2004-0975 security flaw2018-08-16