First published: Wed Oct 20 2004(Updated: )
The netatalk package in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users to overwrite files via a symlink attack on temporary files.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netatalk | =1.6.4 | |
Netatalk | =1.5_pre6 | |
Netatalk | =1.6.1 | |
Red Hat Fedora Core | =core_2.0 | |
Mandriva Linux Corporate Server | =2.1 | |
Mandrake Linux | =9.2 | |
Mandrake Linux | =10.1 | |
Mandrake Linux | =9.2 | |
Mandrake Linux | =10.0 | |
Red Hat Fedora Core | =core_3.0 | |
Mandriva Linux Corporate Server | =2.1 | |
Mandrake Linux | =10.0 | |
Mandrake Linux | =10.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0974 is considered a moderate severity vulnerability due to its potential for local users to overwrite files.
To fix CVE-2004-0974, users should update the netatalk package to the latest version that addresses this vulnerability.
CVE-2004-0974 affects local users of Trustix Secure Linux and several versions of the netatalk package.
CVE-2004-0974 is associated with a symlink attack that allows local users to overwrite temporary files.
CVE-2004-0974 is a local vulnerability, meaning it can only be exploited by users with access to the affected system.