CVE-2004-1107

Properties

Published:
09.01.2005
Updated:
20.10.2005
Patch available:
Severity:
Low
  • CVSS vector:
    (AV:L/AC:L/Au:NR/C:N/I:C/A:N/B:N) Approximated
    Product:
    Gentoo: Gentoo Linux

    Vulnerability description

    dispatch-conf in Portage 2.0.51-r2 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files.

    References:

    Security Focus: http://www.securityfocus.com/bid/11616
    ISS X-Force: http://xforce.iss.net/xforce/xfdb/17986
    Gentoo: http://www.gentoo.org/security/en/glsa/glsa-200411-13.xml
    CONFIRM: http://bugs.gentoo.org/show_bug.cgi?id=69147
    SECUNIA: http://secunia.com/advisories/13108/