bugzilla.redhat.comConfirmation
http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=126940 CVE-2004-2502
IM-Switch - Insecure Temporary File Handling Symbolic Link
Record summary
CVE-2004-2502 has a selected CVSS score of 2.1; EIP currently links 1 catalogued exploit.
Description
im-switch before 11.4-46.1 in Fedora Core 2 allows local users to overwrite arbitrary files via a symlink attack on the imswitcher[PID] temporary file.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBIM-Switch - Insecure Temporary File Handling Symbolic LinkExploitDB exploitby SEKINE TatsuoNot analyzed1 file
References
7packetstormsecurity.org
http://packetstormsecurity.org/0407-advisories/fedora_im-switch_tempfile_race.txt 12037Third-party advisory
http://secunia.com/advisories/12037 7772vdb entry
http://www.osvdb.org/7772 10717vdb entry
http://www.securityfocus.com/bid/10717 fedora-imswitch-symlink(16682)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/16682 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2004-2502