CVE Vulnerabilities

CVE-2004-0647

Published: Aug 06, 2004 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

shorewall 1.4.10c and earlier, and 2.0.x before 2.0.3a, allows local users to overwrite arbitrary files via a symlink attack on the chains-$$ temporary file.

Affected Software

NameVendorStart VersionEnd Version
ShorewallShorewall1.4 (including)1.4 (including)
ShorewallShorewall1.4.1 (including)1.4.1 (including)
ShorewallShorewall1.4.2 (including)1.4.2 (including)
ShorewallShorewall1.4.3 (including)1.4.3 (including)
ShorewallShorewall1.4.3a (including)1.4.3a (including)
ShorewallShorewall1.4.4 (including)1.4.4 (including)
ShorewallShorewall1.4.5 (including)1.4.5 (including)
ShorewallShorewall1.4.6 (including)1.4.6 (including)
ShorewallShorewall1.4.7 (including)1.4.7 (including)
ShorewallShorewall1.4.8 (including)1.4.8 (including)
ShorewallShorewall1.4.9 (including)1.4.9 (including)
ShorewallShorewall1.4.10 (including)1.4.10 (including)
ShorewallShorewall2.0 (including)2.0 (including)
ShorewallShorewall2.0.1 (including)2.0.1 (including)
ShorewallShorewall2.0.2 (including)2.0.2 (including)
ShorewallShorewall2.0.3 (including)2.0.3 (including)

References