CVE-2004-0559: Low severity Usermin Usermin vulnerability
The maketemp.pl script in Usermin 1.070 and 1.080 allows local users to overwrite arbitrary files at install time via a symlink attack on the /tmp/.usermin directory.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0559?
CVE-2004-0559 is considered to have a medium severity due to the potential for local users to exploit the vulnerability.
How do I fix CVE-2004-0559?
To fix CVE-2004-0559, update Usermin to a version later than 1.080 or apply patches that mitigate the symlink attack.
Who is affected by CVE-2004-0559?
CVE-2004-0559 affects local users of Usermin versions 1.070 and 1.080, and potentially certain versions of Webmin.
What type of attack is exploited in CVE-2004-0559?
CVE-2004-0559 is exploited through a symlink attack, allowing local users to overwrite arbitrary files.
Is CVE-2004-0559 still a concern in current systems?
While CVE-2004-0559 is an older vulnerability, systems running vulnerable versions of Usermin or Webmin may still be at risk if not updated.