CVE-2004-0975 describes a local file overwrite vulnerability in the der_chop script within the openssl package, affecting Trustix Secure Linux 1.5 through 2.1, Gentoo, and Mandrakesoft. This flaw allows local attackers to overwrite arbitrary files through a symlink attack on temporary files. The vulnerability has a low severity CVSS score of 2.1 (AV:L/AC:L/Au:N/C:N/I:P/A:N), indicating local access, low attack complexity, and a potential impact limited to partial integrity loss. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage, suggesting it is not a widely targeted or discussed vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.2CPE matchmatch criteria | cpe:2.3:a:mandrakesoft:mandrake_multi_network_firewall:8.2:*:*:*:*:*:*:* | ||
0.9.6CPE matchmatch criteria | cpe:2.3:a:openssl:openssl:0.9.6:*:*:*:*:*:*:* | ||
0.9.6aCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:0.9.6a:*:*:*:*:*:*:* | ||
0.9.6bCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:0.9.6b:*:*:*:*:*:*:* | ||
0.9.6cCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:0.9.6c:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:N/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.