CVE Vulnerabilities

CVE-2004-0564

Published: Dec 23, 2004 | Modified: Jul 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

Roaring Penguin pppoe (rp-ppoe), if installed or configured to run setuid root contrary to its design, allows local users to overwrite arbitrary files. NOTE: the developer has publicly disputed the claim that this is a vulnerability because pppoe is NOT designed to run setuid-root. Therefore this identifier applies only to those configurations and installations under which pppoe is run setuid root despite the developers warnings.

Affected Software

Name Vendor Start Version End Version
Pppoe Roaring_penguin 3.0 (including) 3.0 (including)
Pppoe Roaring_penguin 3.3 (including) 3.3 (including)
Pppoe Roaring_penguin 3.5 (including) 3.5 (including)
Rp-pppoe Ubuntu dapper *
Rp-pppoe Ubuntu devel *
Rp-pppoe Ubuntu edgy *
Rp-pppoe Ubuntu feisty *

References