First published: Fri Dec 31 2004(Updated: )
aStats 1.6.5 allows local users to overwrite arbitrary files via a symlink attack on (1) the aStats-Graphic-Signature-Generation file and (2) certain PNG image files.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Astats | =1.6.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-2605 is considered a moderate severity vulnerability due to its potential impact from local file overwriting.
To fix CVE-2004-2605, ensure that file permissions are properly configured to prevent unauthorized users from creating symbolic links to vulnerable files.
CVE-2004-2605 affects local users of aStats version 1.6.5 who have access to the system where the software is installed.
A symlink attack in CVE-2004-2605 involves creating a symbolic link to a protected file, allowing local users to overwrite files that should be restricted.
CVE-2004-2605 cannot be exploited remotely, as it requires local user access to the system.