CVE-2004-0977

8 documents6 sources
Severity
2.1LOW
EPSS
0.1%
top 74.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 9
Latest updateApr 29

Description

The make_oidjoins_check script in PostgreSQL 7.4.5 and earlier allows local users to overwrite files via a symlink attack on temporary files.

CVSS vector

AV:L/AC:L/C:N/I:P/A:NExploitability: 3.9 | Impact: 2.9

Affected Packages5 packages

Also affects: Enterprise Linux 3.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-6j7m-4j6m-84cw: The make_oidjoins_check script in PostgreSQL 72022-04-29
CVEList
CVE-2004-0977: The make_oidjoins_check script in PostgreSQL 72004-10-20

📋Vendor Advisories

2
Ubuntu
postgresql contributed script vulnerability2004-10-27
Red Hat
security flaw2004-09-30

💬Community

2
Bugzilla
CVE-2004-0977 security flaw2018-08-16
Bugzilla
CAN-2003-0977 fix pushed for RH9, but not FC12004-03-20