CVE-2004-1336: Low severity Debian Tetex-bin vulnerability
Published Dec 23, 2004
·Updated
The xdvizilla script in tetex-bin 2.0.2 creates temporary files with predictable file names, which allows local users to overwrite arbitrary files via a symlink attack.
Affected Software
2 affected components
Debian Tetex-bin=2.0.2
Gentoo Linux
Remediation
Patch Available
Event History
Dec 23, 2004
CVE Published
05:00 AM
Jan 6, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1336?
CVE-2004-1336 is rated as a medium severity vulnerability.
2
How do I fix CVE-2004-1336?
To fix CVE-2004-1336, update the tetex-bin package to a version that does not create predictable temporary file names.
3
What systems are affected by CVE-2004-1336?
CVE-2004-1336 affects Debian teTeX-bin version 2.0.2 and certain installations of Gentoo Linux.
4
What is a symlink attack in the context of CVE-2004-1336?
A symlink attack in CVE-2004-1336 allows local users to overwrite arbitrary files by manipulating predictable temporary file names.
5
Who can exploit CVE-2004-1336?
CVE-2004-1336 can be exploited by local users who have access to the system.