CVE-2004-0977: Low severity postgresql postgresql vulnerability
Published Oct 20, 2004
·Updated
The makeoidjoinscheck script in PostgreSQL 7.4.5 and earlier allows local users to overwrite files via a symlink attack on temporary files.
Affected Software
29 affected componentsFixes available
ubuntu/postgresql<7.5.16.1
7.5.16.1
ubuntu/postgresql<7.5.16.1
7.5.16.1
ubuntu/postgresql-7.4<7.4.12-3
7.4.12-3
ubuntu/postgresql-7.4<7.4.12-3
7.4.12-3
ubuntu/postgresql-8.0<8.0.7-2
8.0.7-2
ubuntu/postgresql-8.1<8.1.9-0ubuntu0.6.06
8.1.9-0ubuntu0.6.06
ubuntu/postgresql-8.1<8.1.9-0ubuntu0.6.10
8.1.9-0ubuntu0.6.10
ubuntu/postgresql-8.1<8.1.8-1ubuntu3
8.1.8-1ubuntu3
ubuntu/postgresql-8.2<8.2.4-0ubuntu0.7.04
8.2.4-0ubuntu0.7.04
debian/postgresql
PostgreSQL postgresql>=7.3.0<7.3.8
PostgreSQL postgresql>=7.4.0<7.4.6
Mandrakesoft Mandrake Linux=9.2
Mandrakesoft Mandrake Linux=9.2
Mandrakesoft Mandrake Linux=10.0
Mandrakesoft Mandrake Linux=10.0
Mandrakesoft Mandrake Linux=10.1
Mandrakesoft Mandrake Linux=10.1
Mandrakesoft Mandrake Linux Corporate Server=2.1
Mandrakesoft Mandrake Linux Corporate Server=2.1
redhat Enterprise Linux=3.0
redhat Enterprise Linux=3.0
redhat Enterprise Linux=3.0
redhat Enterprise Linux Desktop=3.0
Trustix Secure Linux=2.0
Trustix Secure Linux=2.1
PostgreSQL postgresql=7.2.1
PostgreSQL postgresql=7.4.3
PostgreSQL postgresql=7.4.5
Remediation
Patch Available
Patch Available
Event History
Oct 20, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Jun 13, 2024
Data Sourced
via Launchpad·04:22 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0977?
CVE-2004-0977 has a moderate severity rating due to its potential for local file overwriting through symlink attacks.
2
How do I fix CVE-2004-0977?
To fix CVE-2004-0977, upgrade to PostgreSQL version 7.5.16.1 or later.
3
What systems are affected by CVE-2004-0977?
CVE-2004-0977 affects PostgreSQL versions 7.4.5 and earlier.
4
Can local users exploit CVE-2004-0977?
Yes, local users can exploit CVE-2004-0977 to overwrite files.
5
Is there a workaround for CVE-2004-0977?
A direct workaround for CVE-2004-0977 is to restrict access to the affected script and its temporary files.