CVE-2004-0107: Medium severity sysstat sysstat vulnerability
Published Mar 16, 2004
·Updated
The (1) post and (2) trigger scripts in sysstat 4.0.7 and earlier allow local users to overwrite arbitrary files via symlink attacks on temporary files, a different vulnerability than CVE-2004-0108.
Affected Software
12 affected components
sysstat sysstat=4.1.5
sysstat sysstat=4.1.3
sysstat sysstat=4.1.6
sysstat sysstat=4.1.2
sysstat sysstat=4.0.7
sysstat sysstat=4.1.1
sysstat sysstat=5.0.1
redhat Sysstat=4.0.7-3
SGI ProPack=2.3
sysstat sysstat=4.1.7
SGI ProPack=2.4
sysstat sysstat=4.1.4
Remediation
Patch Available
Patch Available
Event History
Mar 16, 2004
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0107?
CVE-2004-0107 has a moderate severity rating due to its potential for local file overwrite vulnerabilities.
2
How do I fix CVE-2004-0107?
To fix CVE-2004-0107, upgrade to sysstat version 4.1.0 or later.
3
What systems are affected by CVE-2004-0107?
CVE-2004-0107 affects sysstat versions 4.0.7 and earlier, as well as specific versions of SGI ProPack.
4
What type of attack does CVE-2004-0107 involve?
CVE-2004-0107 involves symlink attacks on temporary files allowing local users to overwrite arbitrary files.
5
Is CVE-2004-0107 a remote vulnerability?
No, CVE-2004-0107 is classified as a local vulnerability, meaning it can only be exploited by local users.