Vulnerability Description
The (1) write_list and (2) dump_curr_list functions in Net-Acct before 0.71 allows local users to overwrite arbitrary files via a symlink attack on temporary files.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ulrich Callmeier | Net-Acct | 0.6 |
References
- http://exorsus.net/projects/net-acct/net-acct-notempfiles.patchVendor Advisory
- http://marc.info/?l=bugtraq&m=109466910232385&w=2
- http://secunia.com/advisories/12476PatchVendor Advisory
- http://www.debian.org/security/2004/dsa-559PatchVendor Advisory
- http://www.securityfocus.com/bid/11125PatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17283
- http://exorsus.net/projects/net-acct/net-acct-notempfiles.patchVendor Advisory
- http://marc.info/?l=bugtraq&m=109466910232385&w=2
- http://secunia.com/advisories/12476PatchVendor Advisory
- http://www.debian.org/security/2004/dsa-559PatchVendor Advisory
- http://www.securityfocus.com/bid/11125PatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17283
FAQ
What is CVE-2004-0851?
CVE-2004-0851 is a vulnerability with a CVSS score of 2.1 (LOW). The (1) write_list and (2) dump_curr_list functions in Net-Acct before 0.71 allows local users to overwrite arbitrary files via a symlink attack on temporary files.
How severe is CVE-2004-0851?
CVE-2004-0851 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2004-0851?
Check the references section above for vendor advisories and patch information. Affected products include: Ulrich Callmeier Net-Acct.