CVE-2004-1382: Low severity GNU glibc vulnerability
Published Dec 31, 2004
·Updated
The glibcbug script in glibc 2.3.4 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files, a different vulnerability than CVE-2004-0968.
Affected Software
26 affected components
GNU glibc=2.2.2
GNU glibc=2.1.2
GNU glibc=2.0.5
GNU glibc=2.2.5
GNU glibc=2.0.6
GNU glibc=2.1.1
GNU glibc=2.0.3
GNU glibc=2.3.1
GNU glibc=2.3
GNU glibc=2.0
GNU glibc=2.1.1.6
GNU glibc=2.3.10
GNU glibc=2.1
GNU glibc=2.3.4
GNU glibc=2.1.9
GNU glibc=2.3.3
GNU glibc=2.0.1
GNU glibc=2.0.4
GNU glibc=2.0.2
GNU glibc=2.2.1
GNU glibc=2.3.2
GNU glibc=2.1.3.10
GNU glibc=2.2.3
GNU glibc=2.2.4
GNU glibc=2.1.3
GNU glibc=2.2
Remediation
Patch Available
Event History
Dec 31, 2004
CVE Published
05:00 AM
Feb 6, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1382?
CVE-2004-1382 is classified as a medium severity vulnerability.
2
How do I fix CVE-2004-1382?
To fix CVE-2004-1382, upgrade to a patched version of the glibc library that is not affected by this vulnerability.
3
What versions of glibc are affected by CVE-2004-1382?
CVE-2004-1382 affects glibc versions 2.3.4 and earlier.
4
What type of attack does CVE-2004-1382 involve?
CVE-2004-1382 involves a symlink attack on temporary files which allows local users to overwrite arbitrary files.
5
Is CVE-2004-1382 a local or remote vulnerability?
CVE-2004-1382 is a local vulnerability that can be exploited by local users.