CVE-2004-0851

The (1) write_list and (2) dump_curr_list functions in Net-Acct before 0.71 allows local users to overwrite arbitrary files via a symlink attack on temporary files.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ulrich_callmeier:net-acct:0.6:*:*:*:*:*:*:*
cpe:2.3:a:ulrich_callmeier:net-acct:0.7:*:*:*:*:*:*:*
cpe:2.3:a:ulrich_callmeier:net-acct:0.71:*:*:*:*:*:*:*

History

20 Nov 2024, 23:49

Type Values Removed Values Added
References () http://exorsus.net/projects/net-acct/net-acct-notempfiles.patch - Vendor Advisory () http://exorsus.net/projects/net-acct/net-acct-notempfiles.patch - Vendor Advisory
References () http://marc.info/?l=bugtraq&m=109466910232385&w=2 - () http://marc.info/?l=bugtraq&m=109466910232385&w=2 -
References () http://secunia.com/advisories/12476 - Patch, Vendor Advisory () http://secunia.com/advisories/12476 - Patch, Vendor Advisory
References () http://www.debian.org/security/2004/dsa-559 - Patch, Vendor Advisory () http://www.debian.org/security/2004/dsa-559 - Patch, Vendor Advisory
References () http://www.securityfocus.com/bid/11125 - Patch, Vendor Advisory () http://www.securityfocus.com/bid/11125 - Patch, Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/17283 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/17283 -

Information

Published : 2004-09-08 04:00

Updated : 2024-11-20 23:49


NVD link : CVE-2004-0851

Mitre link : CVE-2004-0851

CVE.ORG link : CVE-2004-0851


JSON object : View

Products Affected

ulrich_callmeier

  • net-acct