CVE
- Id
- 8535
- CVE No.
- CVE-2004-0107
- Status
- Candidate
- Description
- The (1) post and (2) trigger scripts in sysstat 4.0.7 and earlier allow local users to overwrite arbitrary files via symlink attacks on temporary files, a different vulnerability than CVE-2004-0108.
- Phase
- Modified (20100819)
- Votes
- ACCEPT(4) Armstrong, Baker, Cole, Wall | MODIFY(2) Cox, Frech | NOOP(1) Christey
- Comments
- Frech> XF:sysstat-post-trigger-symlink(15428) | http://xforce.iss.net/xforce/xfdb/15428 | Cox> This issue is in the vendor packaging of sysstat, not sysstat itself, | and does not apply to a particular version of upstream | sysstat. Suggest "trigger scripts in various vendors packaging of | syssstat allows local users..." or "in the Red Hat packaging of sysstat" | Christey> CIAC:O-097 | URL:http://www.ciac.org/ciac/bulletins/o-097.shtml | XF:sysstat-post-trigger-symlink(15428) | URL:http://xforce.iss.net/xforce/xfdb/15428 | BID:9838 | URL:http://www.securityfocus.com/bid/9838 | Christey> FEDORA:FEDORA-2004-1372 | URL:https://bugzilla.fedora.us/show_bug.cgi?id=1372