| Vulnerability Name: | CVE-2004-2502 (CCN-16682) | ||||||||
| Assigned: | 2004-07-13 | ||||||||
| Published: | 2004-07-13 | ||||||||
| Updated: | 2017-07-11 | ||||||||
| Summary: | im-switch before 11.4-46.1 in Fedora Core 2 allows local users to overwrite arbitrary files via a symlink attack on the imswitcher[PID] temporary file. | ||||||||
| CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L)
| ||||||||
| CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N)
| ||||||||
| Vulnerability Type: | CWE-Other | ||||||||
| Vulnerability Consequences: | File Manipulation | ||||||||
| References: | Source: CONFIRM Type: UNKNOWN http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=126940 Source: MITRE Type: CNA CVE-2004-2502 Source: CCN Type: Fedora Project Download Server Web page Fedora Project, sponsored by Red Hat Source: MISC Type: Exploit, Vendor Advisory http://packetstormsecurity.org/0407-advisories/fedora_im-switch_tempfile_race.txt Source: CCN Type: SA12037 Fedora im-switch Insecure Temporary File Creation Vulnerability Source: SECUNIA Type: Patch, Vendor Advisory 12037 Source: OSVDB Type: Exploit 7772 Source: CCN Type: OSVDB ID: 7772 Fedora im-switch imswitcher[PID] Temporary File Symlink Arbitrary File Overwrite Source: BID Type: Exploit, Patch 10717 Source: CCN Type: BID-10717 IM-Switch Insecure Temporary File Handling Symbolic Link Vulnerability Source: XF Type: UNKNOWN fedora-imswitch-symlink(16682) Source: XF Type: UNKNOWN fedora-imswitch-symlink(16682) | ||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
| BACK | |||||||||