Vulnerabilities > CVE-2004-0404 - Unspecified vulnerability in Psionic Logcheck

047910
CVSS 1.2 - LOW
Attack vector
LOCAL
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
local
high complexity
psionic
nessus

Summary

logcheck before 1.1.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary directory in /var/tmp.

Vulnerable Configurations

Part Description Count
Application
Psionic
1

Nessus

  • NASL familyMandriva Local Security Checks
    NASL idMANDRAKE_MDKSA-2004-155.NASL
    descriptionA vulnerability was discovered in the logcheck program by Christian Jaeger. This could potentially lead to a local attacker overwriting files with root privileges. The updated packages have been patched to prevent the problem.
    last seen2020-06-01
    modified2020-06-02
    plugin id16036
    published2004-12-23
    reporterThis script is Copyright (C) 2004-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/16036
    titleMandrake Linux Security Advisory : logcheck (MDKSA-2004:155)
  • NASL familyDebian Local Security Checks
    NASL idDEBIAN_DSA-488.NASL
    descriptionChristian Jaeger reported a bug in logcheck which could potentially be exploited by a local user to overwrite files with root privileges. logcheck utilized a temporary directory under /var/tmp without taking security precautions. While this directory is created when logcheck is installed, and while it exists there is no vulnerability, if at any time this directory is removed, the potential for exploitation exists.
    last seen2020-06-01
    modified2020-06-02
    plugin id15325
    published2004-09-29
    reporterThis script is Copyright (C) 2004-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/15325
    titleDebian DSA-488-1 : logcheck - insecure temporary directory