CVE-2004-1167: Medium severity gentoo mirrorselect vulnerability
Published Dec 10, 2004
·Updated
mirrorselect before 0.89 creates temporary files in a world-writable location with predictable file names, which allows remote attackers to overwrite arbitrary files via a symlink attack.
Affected Software
9 affected components
Gentoo Mirrorselect=0.88
Gentoo Mirrorselect=0.84
Gentoo Mirrorselect=0.86
Gentoo Mirrorselect=0.83
Gentoo Mirrorselect=0.81
Gentoo Mirrorselect=0.85
Gentoo Mirrorselect=0.87
Gentoo Mirrorselect=0.82
Gentoo Mirrorselect=0.80
Remediation
Patch Available
Event History
Dec 10, 2004
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1167?
CVE-2004-1167 is considered to have a moderate severity due to the potential for remote attackers to overwrite arbitrary files.
2
How do I fix CVE-2004-1167?
To fix CVE-2004-1167, update mirrorselect to version 0.89 or later.
3
What software does CVE-2004-1167 affect?
CVE-2004-1167 affects multiple versions of Gentoo's mirrorselect, specifically versions prior to 0.89.
4
What type of attack is associated with CVE-2004-1167?
CVE-2004-1167 is associated with a symlink attack that exploits predictable temporary file creation.
5
Is CVE-2004-1167 a local or remote vulnerability?
CVE-2004-1167 is a remote vulnerability that allows attackers to exploit it over the network.