Lucene search

K
cve[email protected]CVE-2004-0107
HistoryApr 15, 2004 - 4:00 a.m.

CVE-2004-0107

2004-04-1504:00:00
web.nvd.nist.gov
30
sysstat
symlink attack
cve-2004-0107
nvd

4.6 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

6.1 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

10.7%

The (1) post and (2) trigger scripts in sysstat 4.0.7 and earlier allow local users to overwrite arbitrary files via symlink attacks on temporary files, a different vulnerability than CVE-2004-0108.

Affected configurations

NVD
Node
redhatsysstatMatch4.0.7-3i386
OR
sgipropackMatch2.3
OR
sgipropackMatch2.4
OR
sysstatsysstatMatch4.0.7
OR
sysstatsysstatMatch4.1.1
OR
sysstatsysstatMatch4.1.2
OR
sysstatsysstatMatch4.1.3
OR
sysstatsysstatMatch4.1.4
OR
sysstatsysstatMatch4.1.5
OR
sysstatsysstatMatch4.1.6
OR
sysstatsysstatMatch4.1.7
OR
sysstatsysstatMatch5.0.1

4.6 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

6.1 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

10.7%