PT-2004-1018 · Debian · Debmake
Javier Fernández-Sanguino Peña
·
Published
2004-12-31
·
Updated
2019-07-31
·
CVE-2004-1179
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
debmake versions 3.6.x through 3.6.9
debmake versions 3.7.x through 3.7.6
Description
The issue allows local users to overwrite arbitrary files via a symlink attack on temporary directories. Multiple vulnerabilities in the debmake package of the Debian GNU/Linux operating system can be exploited by a local attacker, potentially leading to a breach of protected information integrity.
Recommendations
For debmake versions 3.6.x through 3.6.9, update to version 3.6.10 or later.
For debmake versions 3.7.x through 3.7.6, update to version 3.7.7 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debmake