CVE-2004-1901: Medium severity Gentoo Linux vulnerability
Published Dec 31, 2004
·Updated
Portage before 2.0.50-r3 allows local users to overwrite arbitrary files via a hard link attack on the lockfiles.
Affected Software
11 affected components
Gentoo Linux=1.4-rc1
Gentoo Linux=1.4-rc3
Gentoo Linux=1.4
Gentoo Linux=1.4-rc2
Gentoo Linux=1.4
Gentoo Linux=1.4-rc1
Gentoo Linux=1.4-rc2
Gentoo Linux=1.4-rc3
Gentoo portage<2.0.50
Gentoo portage=2.0.50
Gentoo Linux=1.4
Remediation
Patch Available
Patch Available
Patch Available
Event History
Dec 31, 2004
CVE Published
05:00 AM
May 10, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1901?
CVE-2004-1901 has a medium severity rating due to the potential for local users to overwrite arbitrary files.
2
How do I fix CVE-2004-1901?
To fix CVE-2004-1901, update to a version of Portage that is 2.0.50 or newer.
3
Which versions of Gentoo Linux are affected by CVE-2004-1901?
Gentoo Linux versions 1.4-rc1, 1.4-rc2, and 1.4-rc3 are affected by CVE-2004-1901.
4
Can CVE-2004-1901 be exploited remotely?
CVE-2004-1901 cannot be exploited remotely as it requires local user access.
5
What is a hard link attack in the context of CVE-2004-1901?
A hard link attack in CVE-2004-1901 allows a malicious local user to create hard links that point to sensitive system files, potentially allowing them to overwrite those files.