CVE-2004-0422: Low severity GNU Flim vulnerability
Published May 6, 2004
·Updated
flim before 1.14.3 creates temporary files insecurely, which allows local users to overwrite arbitrary files of the Emacs user via a symlink attack.
Affected Software
1 affected component
GNU Flim<=1.14.2
Remediation
Patch Available
Event History
May 6, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0422?
The severity of CVE-2004-0422 is classified as moderate due to the potential for local users to overwrite arbitrary files.
2
How do I fix CVE-2004-0422?
To fix CVE-2004-0422, update to Gnu Flim version 1.14.3 or later to secure temporary file creation.
3
Who is affected by CVE-2004-0422?
CVE-2004-0422 affects users of Gnu Flim versions prior to 1.14.3 who may be susceptible to symlink attacks.
4
What type of attack is associated with CVE-2004-0422?
CVE-2004-0422 is associated with a symlink attack that allows local users to manipulate temporary files.
5
Is CVE-2004-0422 still a concern today?
While CVE-2004-0422 is an older vulnerability, systems running vulnerable versions should still be upgraded to prevent potential exploitation.