CVE-2004-0966
Summary
| CVE | CVE-2004-0966 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2005-02-09 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | The (1) autopoint and (2) gettextize scripts in the GNU gettext package 1.14 and later versions, as used in Trustix Secure Linux 1.5 through 2.1 and other operating systems, allows local users to overwrite files via a symlink attack on temporary files. |
Risk And Classification
Primary CVSS: v2.0 2.1 from [email protected]
AV:L/AC:L/Au:N/C:N/I:P/A:N
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:L/AC:L/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Gnu | Gettext | 0.14.1 | All | All | All |
| Operating System | Ubuntu | Ubuntu Linux | 4.1 | All | ia64 | All |
| Operating System | Ubuntu | Ubuntu Linux | 4.1 | All | ppc | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| www.trustix.org/errata/2004/0050 | af854a3a-2127-422b-91ae-364da2661108 | www.trustix.org | |
| [FLSA-2006:136323] Updated gettext package fixes security issues | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| 136323 – CAN-2004-0966 temporary file vulnerabilities in various gettext scripts. | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| '[OpenPKG-SA-2004.055] OpenPKG Security Advisory (gettext)' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| usn/usn-5-1 - Ubuntu Linux | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | |
| GNU GetText Unspecified Insecure Temporary File Creation Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch, Vendor Advisory |
| Advisories - Mandriva | af854a3a-2127-422b-91ae-364da2661108 | wwwnew.mandriva.com | |
| Gentoo Linux Documentation -- gettext: Insecure temporary file handling | af854a3a-2127-422b-91ae-364da2661108 | www.gentoo.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.