PT-2004-1680 · Mandrake · Mandrake Corporate Server+2

Published

2004-06-23

·

Updated

2017-07-11

·

CVE-2004-0581

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Mandrake Linux versions 9.1 through 10.0 Mandrake Corporate Server version 2.1
Description The issue allows local users to delete arbitrary files via a symlink attack on files in /tmp, specifically exploiting the ksymoops-gznm script.
Recommendations For Mandrake Linux versions 9.1 through 10.0, consider removing the vulnerable ksymoops-gznm script or restricting its execution to prevent arbitrary file deletion. For Mandrake Corporate Server version 2.1, consider removing the vulnerable ksymoops-gznm script or restricting its execution to prevent arbitrary file deletion.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-0581

Affected Products

Mandrake Corporate Server
Mandrake Linux
Ksymoops-Gznm