CVE-2004-0217: High severity Symantec AntiVirus Scan Engine vulnerability
The LiveUpdate capability (liveupdate.sh) in Symantec AntiVirus Scan Engine 4.0 and 4.3 for Red Hat Linux allows local users to create or append to arbitrary files via a symlink attack on /tmp/LiveUpdate.log.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0217?
CVE-2004-0217 is considered a medium severity vulnerability due to its exploitation potential through local user access.
How do I fix CVE-2004-0217?
To fix CVE-2004-0217, ensure that LiveUpdate scripts do not allow symlink attacks by properly securing temporary file usage.
Who is affected by CVE-2004-0217?
CVE-2004-0217 affects users of Symantec AntiVirus Scan Engine versions 4.0 and 4.3 running on Red Hat Linux.
What type of attack is associated with CVE-2004-0217?
CVE-2004-0217 is associated with a symlink attack, allowing local users to manipulate files arbitrarily.
What software versions are vulnerable to CVE-2004-0217?
Symantec AntiVirus Scan Engine versions 4.0 and 4.3 for Red Hat Linux are vulnerable to CVE-2004-0217.