CVE-2004-0497: Low severity Conectiva Linux vulnerability
Published Jul 6, 2004
·Updated
Unknown vulnerability in Linux kernel 2.x may allow local users to modify the group ID of files, such as NFS exported files in kernel 2.4.
Affected Software
22 affected components
Conectiva Linux=10
Mandrakesoft Mandrake Multi Network Firewall=8.2
Trustix Secure Linux=2.0
Mandrakesoft Mandrake Linux Corporate Server=2.1
SUSE SuSE Linux=9.0
SUSE SuSE Linux=8.2
redhat Enterprise Linux=3.0
redhat Enterprise Linux=2.1
Mandrakesoft Mandrake Linux=9.2
redhat Enterprise Linux=2.1
SUSE SuSE Linux=8.0
Linux Linux kernel=2.0
Trustix Secure Linux=2
SUSE SuSE Linux=9.1
redhat Enterprise Linux=3.0
redhat Enterprise Linux=2.1
Mandrakesoft Mandrake Linux=10.0
Trustix Secure Linux=2.1
Mandrakesoft Mandrake Linux=9.1
Gentoo Linux
SUSE SuSE Linux=8.1
redhat Enterprise Linux=3.0
Remediation
Patch Available
Event History
Jul 6, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0497?
CVE-2004-0497 is classified as a low severity vulnerability that allows local users to modify group IDs of files.
2
How do I fix CVE-2004-0497?
To fix CVE-2004-0497, you should update your Linux kernel to the latest patched version provided by your distribution.
3
Which Linux distributions are affected by CVE-2004-0497?
CVE-2004-0497 affects multiple Linux distributions including Mandrake, Red Hat, SUSE, and Conectiva.
4
Can CVE-2004-0497 be exploited remotely?
No, CVE-2004-0497 can only be exploited by local users with access to the system.
5
What type of vulnerability is CVE-2004-0497?
CVE-2004-0497 is an unauthorized access vulnerability that affects file permissions in the Linux kernel.