cbcvebase.
CVE-2004-1000
published 2004-01-10

CVE-2004-1000: lintian 1.23 and earlier removes the working directory even if it was not created by lintian, which may allow local users to delete arbitrary files or…

PriorityP410low2.1CVSS 2.0
AVLACLAuNCNINAP
EPSS
0.35%
27.7th percentile
lintian 1.23 and earlier removes the working directory even if it was not created by lintian, which may allow local users to delete arbitrary files or directories via a symlink attack.

Affected

6 ranges
VendorProductVersion rangeFixed in
debianlintian< lintian 1.23.6 (bookworm)lintian 1.23.6 (bookworm)
debianlintian
debianlintian>= 0 < 1.23.61.23.6
debianlintian>= 0 < 1.23.61.23.6
debianlintian>= 0 < 1.23.61.23.6
debianlintian>= 0 < 1.23.61.23.6

CVSS provenance

nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv2.1LOW
vendor_debian2.1LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.