CVE-2004-0969: Low severity gnu groff vulnerability
The groffer script in the Groff package 1.18 and later versions, as used in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users to overwrite files via a symlink attack on temporary files.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0969?
CVE-2004-0969 is classified as a moderate severity vulnerability due to its potential for local privilege escalation.
How do I fix CVE-2004-0969?
To fix CVE-2004-0969, update the Groff package to a patched version that mitigates the symlink attack.
Who is affected by CVE-2004-0969?
CVE-2004-0969 affects local users on systems running Groff version 1.18 and later, including various Linux distributions.
What is the impact of CVE-2004-0969?
The impact of CVE-2004-0969 allows local users to overwrite files, potentially leading to data loss or system compromise.
Is CVE-2004-0969 common in older systems?
Yes, CVE-2004-0969 is more common in older systems and configurations using vulnerable versions of Groff.