Vulnerability Description
The LiveUpdate capability (liveupdate.sh) in Symantec AntiVirus Scan Engine 4.0 and 4.3 for Red Hat Linux allows local users to create or append to arbitrary files via a symlink attack on /tmp/LiveUpdate.log.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Symantec | Antivirus Scan Engine | 4.0 |
| Redhat | Linux | - |
Related Weaknesses (CWE)
References
- http://marc.info/?l=bugtraq&m=107694800908164&w=2ExploitMailing List
- http://www.securityfocus.com/bid/9662Broken LinkPatchThird Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15215Third Party AdvisoryVDB Entry
- http://marc.info/?l=bugtraq&m=107694800908164&w=2ExploitMailing List
- http://www.securityfocus.com/bid/9662Broken LinkPatchThird Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15215Third Party AdvisoryVDB Entry
FAQ
What is CVE-2004-0217?
CVE-2004-0217 is a vulnerability with a CVSS score of 7.0 (HIGH). The LiveUpdate capability (liveupdate.sh) in Symantec AntiVirus Scan Engine 4.0 and 4.3 for Red Hat Linux allows local users to create or append to arbitrary files via a symlink attack on /tmp/LiveUpd...
How severe is CVE-2004-0217?
CVE-2004-0217 has been rated HIGH with a CVSS base score of 7.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2004-0217?
Check the references section above for vendor advisories and patch information. Affected products include: Symantec Antivirus Scan Engine, Redhat Linux.