CVE-2004-1452: High severity Gentoo Linux vulnerability
Tomcat before 5.0.27-r3 in Gentoo Linux sets the default permissions on the init scripts as tomcat:tomcat, but executes the scripts with root privileges, which could allow local users in the tomcat group to execute arbitrary commands as root by modifying the scripts.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1452?
CVE-2004-1452 is considered a high severity vulnerability due to the potential for local users to gain root access.
How do I fix CVE-2004-1452?
To fix CVE-2004-1452, change the permissions on Tomcat init scripts to restrict access to the tomcat group only.
Who is affected by CVE-2004-1452?
CVE-2004-1452 affects users of Gentoo Linux versions including 1.4, 1.4-rc1, and others listed in the vulnerability details.
What types of attacks are possible due to CVE-2004-1452?
Possible attacks include local privilege escalation, allowing an attacker to execute arbitrary commands with root privileges.
Is CVE-2004-1452 still a relevant threat today?
While CVE-2004-1452 is an older vulnerability, systems using affected versions of Gentoo Linux remain at risk if not patched.