PT-2004-1735 · Shorewall · Shorewall
Published
2004-07-13
·
Updated
2017-07-11
·
CVE-2004-0647
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
shorewall versions 1.4.10c and earlier
shorewall versions 2.0.x before 2.0.3a
Description
The issue allows local users to overwrite arbitrary files via a symlink attack on the
chains-$$ temporary file.Recommendations
For shorewall versions 1.4.10c and earlier, update to a version later than 1.4.10c.
For shorewall versions 2.0.x before 2.0.3a, update to version 2.0.3a or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Shorewall