CVE-2004-0256: Low severity GNU libtool vulnerability
Published Sep 1, 2004
·Updated
GNU libtool before 1.5.2, during compile time, allows local users to overwrite arbitrary files via a symlink attack on libtool directories in /tmp.
Affected Software
13 affected components
GNU libtool=1.3.4
GNU libtool=1.5
GNU libtool=1.4
GNU libtool=1.4.3
GNU libtool=1.3.3
GNU libtool=1.0
GNU libtool=1.3.5
GNU libtool=1.4.2
GNU libtool=1.2
GNU libtool=1.3
GNU libtool=1.4.1
GNU libtool=1.3.2
GNU libtool=1.1
Remediation
Patch Available
Event History
Sep 1, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0256?
CVE-2004-0256 is classified as a medium severity vulnerability due to the potential for local users to overwrite arbitrary files.
2
How do I fix CVE-2004-0256?
To mitigate CVE-2004-0256, upgrade to GNU Libtool version 1.5.2 or later.
3
What versions of GNU Libtool are affected by CVE-2004-0256?
CVE-2004-0256 affects GNU Libtool versions from 1.0 to 1.5 inclusive.
4
What type of attack does CVE-2004-0256 involve?
CVE-2004-0256 involves a symlink attack that allows local users to exploit vulnerable libtool directories.
5
Who is impacted by CVE-2004-0256?
Local users on systems running vulnerable versions of GNU Libtool are impacted by CVE-2004-0256.