CVE-2004-0971: Low severity mit kerberos 5 vulnerability
The krb5-send-pr script in the kerberos5 (krb5) package in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users to overwrite files via a symlink attack on temporary files.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-0971?
CVE-2004-0971 is classified as a high severity vulnerability due to its potential for local users to execute unauthorized file modifications.
How do I fix CVE-2004-0971?
To mitigate CVE-2004-0971, ensure that the krb5-send-pr script does not create temporary files in world-writable directories or apply available security patches from your Linux distribution.
Which systems are affected by CVE-2004-0971?
CVE-2004-0971 affects Trustix Secure Linux versions 1.5 through 2.1 and potentially other operating systems that utilize vulnerable versions of the krb5 package.
What is a symlink attack in the context of CVE-2004-0971?
In the context of CVE-2004-0971, a symlink attack allows a local user to create a symbolic link to a sensitive file, enabling them to overwrite it during the execution of the vulnerable script.
Is there any way to detect if CVE-2004-0971 is present in a system?
Yes, you can check for the presence of vulnerable versions of the krb5 package and review system logs for any unauthorized file modifications to determine if CVE-2004-0971 is exploited.