First published: Fri Sep 24 2004(Updated: )
The maketemp.pl script in Usermin 1.070 and 1.080 allows local users to overwrite arbitrary files at install time via a symlink attack on the /tmp/.usermin directory.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Webmin Usermin | =1.070 | |
Webmin | =1.0.20 | |
Webmin Usermin | =1.040 | |
Webmin Usermin | =1.060 | |
Webmin | =1.1.50 | |
Webmin | =1.0.60 | |
Webmin Usermin | =1.080 | |
Webmin | =1.1.00 | |
Webmin | =1.1.30 | |
Webmin | =1.1.21 | |
Webmin | =1.0.00 | |
Webmin | =1.0.90 | |
Webmin Usermin | =1.010 | |
Webmin | =1.1.40 | |
Webmin Usermin | =1.020 | |
Webmin Usermin | =1.051 | |
Webmin Usermin | =1.000 | |
Webmin Usermin | =1.030 | |
Webmin | =1.0.70 | |
Webmin | =1.0.50 | |
Webmin | =1.0.80 | |
Webmin | =1.1.10 | |
Mandriva Linux Corporate Server | =2.1 | |
Mandrake Linux | =9.2 | |
Mandrake Linux | =9.2 | |
Mandrake Linux | =10.0 | |
Mandriva Linux Corporate Server | =2.1 | |
Mandrake Linux | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0559 is considered to have a medium severity due to the potential for local users to exploit the vulnerability.
To fix CVE-2004-0559, update Usermin to a version later than 1.080 or apply patches that mitigate the symlink attack.
CVE-2004-0559 affects local users of Usermin versions 1.070 and 1.080, and potentially certain versions of Webmin.
CVE-2004-0559 is exploited through a symlink attack, allowing local users to overwrite arbitrary files.
While CVE-2004-0559 is an older vulnerability, systems running vulnerable versions of Usermin or Webmin may still be at risk if not updated.