PT-2004-1019 · Debian · Trr19

Published

2004-01-29

·

Updated

2017-07-11

·

CVE-2004-0047

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions trr19 versions 1.0
Description The issue concerns multiple vulnerabilities in the trr19 package of the Debian GNU/Linux operating system, which can be exploited by a local attacker to compromise the confidentiality, integrity, and availability of protected information. The vulnerabilities allow local users to potentially gain privileges due to improper privilege dropping before executing system commands.
Recommendations For trr19 version 1.0, consider restricting access to system commands until a patch is available to prevent local users from gaining privileges. As a temporary workaround, ensure that all system commands are executed with proper privilege handling to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-02956
CVE-2004-0047
DSA-430

Affected Products

Trr19