Vulnerabilities > CVE-2004-0851 - Unspecified vulnerability in Ulrich Callmeier Net-Acct 0.6/0.7/0.71
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN ulrich-callmeier
nessus
Summary
The (1) write_list and (2) dump_curr_list functions in Net-Acct before 0.71 allows local users to overwrite arbitrary files via a symlink attack on temporary files.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 3 |
Nessus
NASL family | Debian Local Security Checks |
NASL id | DEBIAN_DSA-559.NASL |
description | Stefan Nordhausen has identified a local security hole in net-acct, a user-mode IP accounting daemon. Old and redundant code from some time way back in the past created a temporary file in an insecure fashion. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 15657 |
published | 2004-11-10 |
reporter | This script is Copyright (C) 2004-2019 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/15657 |
title | Debian DSA-559-1 : net-acct - insecure temporary file |
code |
|
References
- http://exorsus.net/projects/net-acct/net-acct-notempfiles.patch
- http://exorsus.net/projects/net-acct/net-acct-notempfiles.patch
- http://marc.info/?l=bugtraq&m=109466910232385&w=2
- http://marc.info/?l=bugtraq&m=109466910232385&w=2
- http://secunia.com/advisories/12476
- http://secunia.com/advisories/12476
- http://www.debian.org/security/2004/dsa-559
- http://www.debian.org/security/2004/dsa-559
- http://www.securityfocus.com/bid/11125
- http://www.securityfocus.com/bid/11125
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17283
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17283