PT-2004-1680 · Mandrake · Mandrake Corporate Server+2
Published
2004-06-23
·
Updated
2017-07-11
·
CVE-2004-0581
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Mandrake Linux versions 9.1 through 10.0
Mandrake Corporate Server version 2.1
Description
The issue allows local users to delete arbitrary files via a symlink attack on files in /tmp, specifically exploiting the ksymoops-gznm script.
Recommendations
For Mandrake Linux versions 9.1 through 10.0, consider removing the vulnerable ksymoops-gznm script or restricting its execution to prevent arbitrary file deletion.
For Mandrake Corporate Server version 2.1, consider removing the vulnerable ksymoops-gznm script or restricting its execution to prevent arbitrary file deletion.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mandrake Corporate Server
Mandrake Linux
Ksymoops-Gznm