{ "id": "CVE-2004-0647", "sourceIdentifier": "cve@mitre.org", "published": "2004-08-06T04:00:00.000", "lastModified": "2017-07-11T01:30:20.543", "vulnStatus": "Modified", "descriptions": [ { "lang": "en", "value": "shorewall 1.4.10c and earlier, and 2.0.x before 2.0.3a, allows local users to overwrite arbitrary files via a symlink attack on the chains-$$ temporary file." }, { "lang": "es", "value": "shorewall 1.4.10c y anteriores, y 2.0.x anteriores a 2.0.3a permiten a usuarios locales sobreescribir ficheros de su elecci\u00f3n mediante un ataque de enlaces simb\u00f3licos en el fichero temporal chain-$$." } ], "metrics": { "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:P", "accessVector": "LOCAL", "accessComplexity": "LOW", "authentication": "NONE", "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "availabilityImpact": "PARTIAL", "baseScore": 4.6 }, "baseSeverity": "MEDIUM", "exploitabilityScore": 3.9, "impactScore": 6.4, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": true, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "NVD-CWE-Other" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:shorewall:shorewall:1.4:*:*:*:*:*:*:*", "matchCriteriaId": "B09DE7E2-CC5F-415B-A392-D68AB5D5183A" }, { "vulnerable": true, "criteria": "cpe:2.3:a:shorewall:shorewall:1.4.1:*:*:*:*:*:*:*", "matchCriteriaId": "F9607C7E-6F86-4912-A376-08AF7BF02C1D" }, { "vulnerable": true, "criteria": "cpe:2.3:a:shorewall:shorewall:1.4.2:*:*:*:*:*:*:*", "matchCriteriaId": "36381169-72B8-4A24-BAF2-BEC34ED111CE" }, { "vulnerable": true, "criteria": "cpe:2.3:a:shorewall:shorewall:1.4.3:*:*:*:*:*:*:*", "matchCriteriaId": "BB8C6C0C-AFFD-4245-9BC8-315449A93630" }, { "vulnerable": true, "criteria": "cpe:2.3:a:shorewall:shorewall:1.4.3a:*:*:*:*:*:*:*", "matchCriteriaId": "755E1346-339F-4910-A360-A54A7C7248CC" }, { "vulnerable": true, "criteria": "cpe:2.3:a:shorewall:shorewall:1.4.4:*:*:*:*:*:*:*", "matchCriteriaId": "5484FDC1-69C9-4E41-AC5C-9F27AAAA21F2" }, { "vulnerable": true, "criteria": "cpe:2.3:a:shorewall:shorewall:1.4.5:*:*:*:*:*:*:*", "matchCriteriaId": "27002D31-C070-438D-B673-883E53604484" }, { "vulnerable": true, "criteria": "cpe:2.3:a:shorewall:shorewall:1.4.6:*:*:*:*:*:*:*", "matchCriteriaId": "51856967-B4E8-492F-9A7D-ABEDA30DD002" }, { "vulnerable": true, "criteria": "cpe:2.3:a:shorewall:shorewall:1.4.7:*:*:*:*:*:*:*", "matchCriteriaId": "C908BE61-EC82-4FFA-9F70-A62DCB61B7E7" }, { "vulnerable": true, "criteria": "cpe:2.3:a:shorewall:shorewall:1.4.8:*:*:*:*:*:*:*", "matchCriteriaId": "F5D91047-9FFE-434F-AA74-8CAD5FFA1D47" }, { "vulnerable": true, "criteria": "cpe:2.3:a:shorewall:shorewall:1.4.9:*:*:*:*:*:*:*", "matchCriteriaId": "F8AAC279-B154-4591-90C8-4026DFE486EA" }, { "vulnerable": true, "criteria": "cpe:2.3:a:shorewall:shorewall:1.4.10:*:*:*:*:*:*:*", "matchCriteriaId": "A6FC0B9A-1B52-4983-A8DB-A27EDB16C399" }, { "vulnerable": true, "criteria": "cpe:2.3:a:shorewall:shorewall:2.0:*:*:*:*:*:*:*", "matchCriteriaId": "FA74BD87-28A4-479B-A02C-C5EF0FE99033" }, { "vulnerable": true, "criteria": "cpe:2.3:a:shorewall:shorewall:2.0.1:*:*:*:*:*:*:*", "matchCriteriaId": "FA3C10C9-AB0C-4CDB-82C2-606FC92799E3" }, { "vulnerable": true, "criteria": "cpe:2.3:a:shorewall:shorewall:2.0.2:*:*:*:*:*:*:*", "matchCriteriaId": "444C2974-82B2-49D9-B6D2-6E6BB19A100B" }, { "vulnerable": true, "criteria": "cpe:2.3:a:shorewall:shorewall:2.0.3:*:*:*:*:*:*:*", "matchCriteriaId": "FF76A1B4-3B30-408B-9E8D-627BA55B44B7" } ] } ] } ], "references": [ { "url": "http://lists.shorewall.net/pipermail/shorewall-announce/2004-June/000385.html", "source": "cve@mitre.org" }, { "url": "http://www.gentoo.org/security/en/glsa/glsa-200407-07.xml", "source": "cve@mitre.org", "tags": [ "Patch", "Vendor Advisory" ] }, { "url": "http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:080", "source": "cve@mitre.org" }, { "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/16651", "source": "cve@mitre.org" } ] }