PT-2004-1680 · Mandrake · Mandrake Corporate Server+2
Publicado
2004-06-23
·
Atualizado
2017-07-11
·
CVE-2004-0581
CVSS v2.0
4.6
Média
| Vetor | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Mandrake Linux versions 9.1 through 10.0
Mandrake Corporate Server version 2.1
Description
The issue allows local users to delete arbitrary files via a symlink attack on files in /tmp, specifically exploiting the ksymoops-gznm script.
Recommendations
For Mandrake Linux versions 9.1 through 10.0, consider removing the vulnerable ksymoops-gznm script or restricting its execution to prevent arbitrary file deletion.
For Mandrake Corporate Server version 2.1, consider removing the vulnerable ksymoops-gznm script or restricting its execution to prevent arbitrary file deletion.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Mandrake Corporate Server
Mandrake Linux
Ksymoops-Gznm