CVE-2004-1000: Low severity Debian Lintian vulnerability
lintian 1.23 and earlier removes the working directory even if it was not created by lintian, which may allow local users to delete arbitrary files or directories via a symlink attack.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
For lintian versions 1.23 and earlier, avoid running lintian in a working directory that was not created for that invocation. Create and use a dedicated temporary working directory (owned by the invoking user) for each lintian run and remove it after the run to prevent local users from exploiting symlink attacks to delete arbitrary files or directories.
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1000?
CVE-2004-1000 is considered a medium severity vulnerability due to its potential for local users to exploit it for file deletion.
How do I fix CVE-2004-1000?
To fix CVE-2004-1000, upgrade to a version of lintian later than 1.23 that addresses the symlink vulnerability.
What software is affected by CVE-2004-1000?
CVE-2004-1000 affects lintian versions 1.23 and earlier, particularly the version 1.2_0.17.1.
What type of attack does CVE-2004-1000 enable?
CVE-2004-1000 enables a symlink attack that can allow a user to delete arbitrary files or directories.
Is CVE-2004-1000 still a threat today?
While CVE-2004-1000 is an older vulnerability, it remains a threat if outdated versions of lintian are still in use.