Back to Database
Status published
Low
CVE-2004-0975
The der_chop script in the openssl package in Trustix Secure...
Vulnerability Description
The der_chop script in the openssl package in Trustix Secure Linux 1.5 through 2.1 and other operating systems allows local users to overwrite files via a symlink attack on temporary files.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2004-0975
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.gentoo.org/security/en/glsa/glsa-200411-15.xml
- http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=136302
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17583
- http://www.trustix.org/errata/2004/0050
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A164
- http://www.debian.org/security/2004/dsa-603
- http://www.redhat.com/support/errata/RHSA-2005-476.html
- http://www.securityfocus.com/bid/11293
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10621
- http://secunia.com/advisories/12973
More from mandrakesoft
View All →CVE-2007-1352
Integer overflow in the FontFileInitTable function in X.Org libXfont before...
Low
3.8
CVE-2005-2377
nss_ldap 181 to versions before 213, as used in Mandrake...
Medium
5
CVE-2005-1379
The LAM runtime environment package (lam-runtime-7.0.6-2mdk) on Mandrake Linux installs...
Medium
4.6
CVE-2004-2395
Memory leak in passwd 0.68 allows local users to cause...
Low
2.1
CVE-2004-2394
Off-by-one error in passwd 0.68 and earlier, when using the...
Low
2.1
Affected Vendor
mandrakesoft
View all reports →Affected Software
mandrake multi network firewall, openssl, linux, mandrake linux, mandrake linux corporate server
Vulnerable Versions:
8.2, 0.9.6, 0.9.6a, 0.9.6b, 0.9.6c, 0.9.6d, 0.9.6e, 0.9.6f, 0.9.6g, 0.9.6h, 0.9.6i, 0.9.6j, 0.9.6k, 0.9.6l, 0.9.6m, 0.9.7c, 0.9.7d, 9.2, 10.0, 10.1, 2.1
Timeline
Official Publish:
October 20th, 2004
Last Modified:
August 8th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.