20040113 SuSE linux 9.0 YaST config Skribt [exploit]mailing list
http://marc.info/?l=bugtraq&m=107402658600437&w=2 CVE-2004-0064
SuSE Linux 9.0 - YaST Configuration Skribt Overwrite Files
Record summary
CVE-2004-0064 has a selected CVSS score of 2.1; EIP currently links 1 catalogued exploit.
Description
The SuSEconfig.gnome-filesystem script for YaST in SuSE 9.0 allows local users to overwrite arbitrary files via a symlink attack on files within the tmp.SuSEconfig.gnome-filesystem.$RANDOM temporary directory.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBSuSE Linux 9.0 - YaST Configuration Skribt Overwrite FilesExploitDB exploitby l0omNot analyzed1 file
References
610623Third-party advisory
http://secunia.com/advisories/10623 3460vdb entry
http://www.osvdb.org/3460 9411vdb entry
http://www.securityfocus.com/bid/9411 1008703vdb entry
http://www.securitytracker.com/id?1008703 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2004-0064