Search

published date: February 9, 2005

CVE-2004-0974 : The netatalk package in...

Description

The netatalk package in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users to overwrite files via a symlink attack on temporary files.

Product(s):

  • Netatalk Open Source Apple File Share Protocol Suite 1.5 Pre6
  • Netatalk Open Source Apple File Share Protocol Suite 1.6.1
  • Netatalk Open Source Apple File Share Protocol Suite 1.6.4
  • MandrakeSoft Mandrake Linux 10.0
  • Mandrakesoft Mandrake Linux 10.0 on AMD64
  • MandrakeSoft Mandrake Linux 10.1

Question to Ask Vendors:

  1. Can you confirm whether your systems are affected by CVE-2004-0974, and if so, what steps are you currently taking to mitigate this vulnerability?
  2. What is your estimated timeline for fully resolving CVE-2004-0974 in your products or services, and how will you communicate updates on this issue to us as your customer?

READY TO GET RESULTS YOU CAN TRUST?