CVE-2004-1895: Low severity SUSE SuSE Linux vulnerability
Published Dec 31, 2004
·Updated
YaST Online Update (YOU) in SuSE 8.2 and 9.0 allows local users to overwrite arbitrary files via a symlink attack on you-$USER/cookies.
Affected Software
3 affected components
SUSE SuSE Linux=9.0
SUSE SuSE Linux=8.2
SUSE SuSE Linux=9.0
Event History
Dec 31, 2004
CVE Published
05:00 AM
May 10, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1895?
CVE-2004-1895 is considered a moderate severity vulnerability.
2
How do I fix CVE-2004-1895?
To fix CVE-2004-1895, it is recommended to update to a patched version of SuSE that addresses the symlink attack.
3
Who is affected by CVE-2004-1895?
CVE-2004-1895 affects local users of SuSE Linux versions 8.2 and 9.0.
4
What type of attack is associated with CVE-2004-1895?
CVE-2004-1895 is associated with a symlink attack that allows local file overwriting.
5
Is CVE-2004-1895 still a concern for current systems?
CVE-2004-1895 is primarily a concern for legacy systems running SuSE 8.2 and 9.0, and is unlikely to affect modern systems.