CVE Vulnerabilities

CVE-2004-0564

Published: Dec 23, 2004 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Roaring Penguin pppoe (rp-ppoe), if installed or configured to run setuid root contrary to its design, allows local users to overwrite arbitrary files. NOTE: the developer has publicly disputed the claim that this is a vulnerability because pppoe is NOT designed to run setuid-root. Therefore this identifier applies only to those configurations and installations under which pppoe is run setuid root despite the developers warnings.

Affected Software

NameVendorStart VersionEnd Version
PppoeRoaring_penguin3.0 (including)3.0 (including)
PppoeRoaring_penguin3.3 (including)3.3 (including)
PppoeRoaring_penguin3.5 (including)3.5 (including)
Rp-pppoeUbuntudapper*
Rp-pppoeUbuntudevel*
Rp-pppoeUbuntuedgy*
Rp-pppoeUbuntufeisty*

References