2.1
CVSSv2

CVE-2004-0851

Published: 08/09/2004 Updated: 11/07/2017
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

The (1) write_list and (2) dump_curr_list functions in Net-Acct prior to 0.71 allows local users to overwrite arbitrary files via a symlink attack on temporary files.

Vulnerable Product Search on Vulmon Subscribe to Product

ulrich callmeier net-acct 0.71

ulrich callmeier net-acct 0.6

ulrich callmeier net-acct 0.7

Vendor Advisories

Stefan Nordhausen has identified a local security hole in net-acct, a user-mode IP accounting daemon Old and redundant code from some time way back in the past created a temporary file in an insecure fashion For the stable distribution (woody) this problem has been fixed in version 071-5woody1 For the unstable distribution (sid) this problem ha ...