CVE-2004-2459: Low severity gnu gnubiff vulnerability
Published Dec 31, 2004
·Updated
Unknown vulnerability in gnubiff 1.2.0 and earlier allows local users to obtain passwords, related to the password table.
Affected Software
9 affected components
GNU gnubiff=1.2.0
GNU gnubiff=1.0.6
GNU gnubiff=1.0.7
GNU gnubiff=1.0.5
GNU gnubiff=1.0.3
GNU gnubiff=1.0.10
GNU gnubiff=1.0.9
GNU gnubiff=1.0.8
GNU gnubiff=1.0.4
Remediation
Patch Available
Event History
Dec 31, 2004
CVE Published
05:00 AM
Aug 20, 2005
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-2459?
CVE-2004-2459 is considered to have critical severity due to the potential unauthorized exposure of user passwords.
2
How do I fix CVE-2004-2459?
To fix CVE-2004-2459, upgrade to a version of Gnubiff later than 1.2.0.
3
Who is affected by CVE-2004-2459?
CVE-2004-2459 affects local users of Gnubiff version 1.2.0 and earlier.
4
What type of vulnerability is CVE-2004-2459?
CVE-2004-2459 is a local privilege escalation vulnerability that allows access to sensitive information.
5
Are there any workarounds for CVE-2004-2459?
Currently, there are no published workarounds for CVE-2004-2459; upgrading the software is recommended.