PT-2004-1742 · Esearch · Ke Search

Published

2004-07-13

·

Updated

2017-07-11

·

CVE-2004-0655

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions esearch version 0.6.1 and earlier
Description The issue allows local users to create arbitrary files via a symlink attack on the esearchdb.py.tmp temporary file.
Recommendations For esearch version 0.6.1 and earlier, consider updating to a newer version that addresses this issue, as a temporary workaround, restrict access to the eupdatedb function in esearch to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-0655

Affected Products

Ke Search