CVE-2004-1108

Properties

Published:
09.01.2005
Updated:
20.10.2005
Patch available:
Severity:
Low
  • CVSS vector:
    (AV:L/AC:L/Au:NR/C:N/I:C/A:N/B:N) Approximated
    Product:
    Gentoo: Gentoo Linux

    Vulnerability description

    qpkg in Gentoolkit 0.2.0_pre10 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary directory.

    References:

    Security Focus: http://www.securityfocus.com/bid/11617
    ISS X-Force: http://xforce.iss.net/xforce/xfdb/17968
    Gentoo: http://www.gentoo.org/security/en/glsa/glsa-200411-13.xml
    Secunia: http://secunia.com/advisories/13108/
    CONFIRM: http://bugs.gentoo.org/show_bug.cgi?id=68846