First published: Thu May 06 2004(Updated: )
flim before 1.14.3 creates temporary files insecurely, which allows local users to overwrite arbitrary files of the Emacs user via a symlink attack.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Gnu Flim | <=1.14.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2004-0422 is classified as moderate due to the potential for local users to overwrite arbitrary files.
To fix CVE-2004-0422, update to Gnu Flim version 1.14.3 or later to secure temporary file creation.
CVE-2004-0422 affects users of Gnu Flim versions prior to 1.14.3 who may be susceptible to symlink attacks.
CVE-2004-0422 is associated with a symlink attack that allows local users to manipulate temporary files.
While CVE-2004-0422 is an older vulnerability, systems running vulnerable versions should still be upgraded to prevent potential exploitation.