CVE-2004-0977
LOW severity · CVSS 2.1
2.1CVSS LOW
Summary
The make_oidjoins_check script in PostgreSQL 7.4.5 and earlier allows local users to overwrite files via a symlink attack on temporary files.
Impact & exploitability
Attack vectorLocal
Attack complexityLow
Privileges required—
User interaction—
Confidentiality impactNone
Integrity impact—
Availability impactNone
Exploit probability (EPSS)0%
AV:L/AC:L/Au:N/C:N/I:P/A:N
Affected products we track (1)
Recommendation
Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.
Official patch: http://www.debian.org/security/2004/dsa-577 ↗
Additional information
- NVD record
- http://www.debian.org/security/2004/dsa-577Patch
- http://www.securityfocus.com/bid/11295Patch
- http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=136300
- http://marc.info/?l=bugtraq&m=109910073808903&w=2Advisory
- http://security.gentoo.org/glsa/glsa-200410-16.xmlAdvisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2004:149Advisory
- http://www.redhat.com/support/errata/RHSA-2004-489.html
- http://www.trustix.org/errata/2004/0050Advisory