← Back

CVE-2004-0559

nvd nist
Published: Oct 20, 2004Modified: Apr 16, 2026

JSON object

Loading...
2.1
Vector
AV:L/AC:L/Au:N/C:N/I:P/A:N
Exploitability: 3.9 / Impact: 2.9
Source: NVD

Description

The maketemp.pl script in Usermin 1.070 and 1.080 allows local users to overwrite arbitrary files at install time via a symlink attack on the /tmp/.usermin directory.

Affected (28)

1 product
Usermin
1 product
Webmin
2 products
Mandrake Linux
Mandrake Linux Corporate Server
Configuration A
22 vulnerable
Vulnerable SoftwareAffected Versions
Usermin
Version 1.000
Version 1.010
Version 1.020
Version 1.030
Version 1.040
Version 1.051
Version 1.060
Version 1.070
Version 1.080
Webmin
Version 1.0.00
Version 1.0.20
Version 1.0.50
Version 1.0.60
Version 1.0.70
Version 1.0.80
Version 1.0.90
Version 1.1.00
Version 1.1.10
Version 1.1.21
Version 1.1.30
Version 1.1.40
Version 1.1.50
Configuration B
6 vulnerable

References (10)

Source: cve@mitre.org
PatchVendor Advisory
Source: cve@mitre.org
PatchVendor Advisory
Source: cve@mitre.org
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.