CVE-2004-0966: Low severity gnu gettext vulnerability
The (1) autopoint and (2) gettextize scripts in the GNU gettext package 1.14 and later versions, as used in Trustix Secure Linux 1.5 through 2.1 and other operating systems, allows local users to overwrite files via a symlink attack on temporary files.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0966?
CVE-2004-0966 has a moderate severity rating due to the potential for local users to exploit symlink vulnerabilities.
How do I fix CVE-2004-0966?
To remediate CVE-2004-0966, update GNU gettext to version 0.14.5-2ubuntu3 or later for Ubuntu and patch your Debian installations to the specified versions.
What platforms are affected by CVE-2004-0966?
CVE-2004-0966 affects GNU gettext version 0.14 and later on multiple platforms, including several versions of Ubuntu and Debian.
Can CVE-2004-0966 be exploited remotely?
CVE-2004-0966 requires local access for exploitation, making it less of a threat compared to remote vulnerabilities.
What is the type of vulnerability for CVE-2004-0966?
CVE-2004-0966 is a symlink attack vulnerability that allows local users to overwrite files.