← Back

CVE-2004-0564

nvd nist
Published: Dec 23, 2004Modified: Apr 16, 2026

JSON object

Loading...
2.1
Vector
AV:L/AC:L/Au:N/C:N/I:P/A:N
Exploitability: 3.9 / Impact: 2.9
Source: NVD

Description

Roaring Penguin pppoe (rp-ppoe), if installed or configured to run setuid root contrary to its design, allows local users to overwrite arbitrary files. NOTE: the developer has publicly disputed the claim that this is a vulnerability because pppoe "is NOT designed to run setuid-root." Therefore this identifier applies *only* to those configurations and installations under which pppoe is run setuid root despite the developer's warnings.

Affected (15)

Pppoe
1 product
Debian Linux
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Roaring Penguin
Version 3.0
Version 3.3
Version 3.5
Configuration B
12 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 3.0
Version 3.0
Version 3.0
Version 3.0
Version 3.0
Version 3.0
Version 3.0
Version 3.0
Version 3.0
Version 3.0
Version 3.0
Version 3.0

References (12)

Timeline

No history available yet.