CVE-2004-2231: Low severity Zero G InstallAnywhere vulnerability
Published Dec 31, 2004
·Updated
Zero G Software InstallAnywhere 5.0.6, 5.0.7, and earlier allows local users to overwrite arbitrary files via a symlink attack on the (1) persistentstate or (2) env.properties.X temporary files.
Affected Software
4 affected components
Zero G InstallAnywhere=5.0.6
Zero G InstallAnywhere=5.0.7
Zero G InstallAnywhere=5.0.6
Zero G InstallAnywhere=5.0.7
Event History
Dec 31, 2004
CVE Published
05:00 AM
Jul 17, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-2231?
The severity of CVE-2004-2231 is considered to be medium due to the potential for local users to overwrite arbitrary files.
2
How do I fix CVE-2004-2231?
To fix CVE-2004-2231, update to a version of Zero G InstallAnywhere later than 5.0.7 that addresses this vulnerability.
3
Who is affected by CVE-2004-2231?
Local users operating Zero G Software InstallAnywhere versions 5.0.6 and 5.0.7 are affected by CVE-2004-2231.
4
What types of attacks are possible with CVE-2004-2231?
CVE-2004-2231 allows for symlink attacks, enabling attackers to overwrite arbitrary files on the system.
5
Is CVE-2004-2231 a remote or local vulnerability?
CVE-2004-2231 is a local vulnerability, meaning it requires local access to exploit.