Vulnerability Name: | CVE-2004-0564 (CCN-17576) | ||||||||
Assigned: | 2004-10-04 | ||||||||
Published: | 2004-10-04 | ||||||||
Updated: | 2017-07-11 | ||||||||
Summary: | Roaring Penguin pppoe (rp-ppoe), if installed or configured to run setuid root contrary to its design, allows local users to overwrite arbitrary files. Note: the developer has publicly disputed the claim that this is a vulnerability because pppoe "is NOT designed to run setuid-root." Therefore this identifier applies *only* to those configurations and installations under which pppoe is run setuid root despite the developer's warnings. | ||||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: MITRE Type: CNA CVE-2004-0564 Source: MANDRAKE Type: UNKNOWN MDKSA-2004:145 Source: BUGTRAQ Type: UNKNOWN 20041208 Re: MDKSA-2004:145 - Updated rp-pppoe packages fix vulnerability Source: DEBIAN Type: Patch, Vendor Advisory DSA-557 Source: DEBIAN Type: DSA-557 rp-pppoe -- missing privilege dropping Source: FEDORA Type: UNKNOWN FLSA:152794 Source: CCN Type: OSVDB ID: 10547 Roaring Penguin PPPoE -D Option Local Privilege Escalation Source: CCN Type: Roaring Penguin Web site OPEN SOURCE PRODUCTS Source: BID Type: Patch, Vendor Advisory 11315 Source: CCN Type: BID-11315 Roaring Penguin PPPoE Arbitrary File Overwrite Vulnerability Source: XF Type: UNKNOWN pppoe-file-overwrite(17576) Source: XF Type: UNKNOWN pppoe-file-overwrite(17576) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Denotes that component is vulnerable | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |