← Vulnerability feed

Vulnerability record · CVE-2004-0975 · published 9 February 2005

CVE-2004-0975: Mandrakesoft mandrake multi network firewall vulnerability

MMandrakesoft · Mandrake Multi Network Firewall

The der_chop script in the openssl package in Trustix Secure Linux 1.5 through 2.1 and other operating systems allows local users to overwrite files via a symlink attack on temporary files.

2.1 CVSS 2.0 Low EPSS 0.42% · top 66.4%
2.1CVSS 2.0 base score
0.42%EPSS exploitation probability, 30 days
NoNot in CISA KEV
5Affected product versions listed by NVD
20References
16 Jun 2026Last modified by NVD

Description

The der_chop script in the openssl package in Trustix Secure Linux 1.5 through 2.1 and other operating systems allows local users to overwrite files via a symlink attack on temporary files.

AV:L/AC:L/Au:N/C:N/I:P/A:N

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2004-0975 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2014-0160OpenSSL TLS/DTLS Heartbeat Extension Out-of-Bounds Read (Heartbleed)OpenSSL 1.0.1 before 1.0.1g mishandles Heartbeat Extension packets in its TLS and DTLS implementations, causing an out-of-bounds read of process memo…KEVEPSS 100%analysed10.0CVE-2009-3245Openssl improper input validation vulnerabilityOpenSSL before 0.9.8m does not check for a NULL return value from bn_wexpand function calls in (1) crypto/bn/bn_div.c, (2) crypto/bn/bn_gf2m.c, (3) c…EPSS 5.8%10.0CVE-2006-3738OpenSSL SSL_get_shared_ciphers buffer overflow via long cipher listOpenSSL versions before 0.9.7l and 0.9.8d contain a buffer overflow in the SSL_get_shared_ciphers function, triggered by a long list of ciphers. The …EPSS 49%analysed10.0CVE-2005-3625Easy software products cups vulnerabilityXpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of servic…EPSS 3.8%10.0CVE-2004-0990Gd graphics library gdlib vulnerabilityInteger overflow in GD Graphics Library libgd 2.0.28 (libgd2), and possibly other versions, allows remote attackers to cause a denial of service and …EPSS 28%10.0CVE-2004-1037TWiki search function allows remote command executionThe search function in TWiki 20030201 passes user-supplied search strings to a shell without sanitizing shell metacharacters, allowing command inject…EPSS 62%analysed10.0CVE-2004-1034Kaffeine player vulnerabilityBuffer overflow in the http_open function in Kaffeine before 0.5, whose code is also used in gxine before 0.3.3, allows remote attackers to cause a d…EPSS 5.7%10.0CVE-2004-1052Bnc vulnerabilityBuffer overflow in the getnickuserhost function in BNC 2.8.9, and possibly other versions, allows remote IRC servers to execute arbitrary code via an…EPSS 3.6%

Source: NIST National Vulnerability Database (record CVE-2004-0975), CISA KEV, FIRST EPSS (scores of 2026-10-05). This page is refreshed as NVD updates the record.