First published: Wed Jun 23 2004(Updated: )
ksymoops-gznm script in Mandrake Linux 9.1 through 10.0, and Corporate Server 2.1, allows local users to delete arbitrary files via a symlink attack on files in /tmp.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU ksymoops | =2.4.5 | |
GNU ksymoops | =2.4.8 | |
GNU ksymoops | =2.4.9 | |
Mandriva Linux Corporate Server | =2.1 | |
Mandrake Linux | =9.2 | |
Mandrake Linux | =9.2 | |
Mandrake Linux | =9.1 | |
Mandrake Linux | =10.0 | |
Mandrake Linux | =9.1 | |
Mandriva Linux Corporate Server | =2.1 | |
Mandrake Linux | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0581 describes a symlink attack that allows local users to delete arbitrary files.
CVE-2004-0581 affects Mandrake Linux versions 9.1 through 10.0, and Corporate Server 2.1 with specific GNU ksymoops versions.
CVE-2004-0581 is classified as having a moderate severity level due to its impact on local user access.
To mitigate CVE-2004-0581, users should ensure they upgrade to patched versions of GNU ksymoops and secure /tmp permissions.
CVE-2004-0581 was published in 2004, highlighting vulnerabilities in older versions of Mandrake Linux.