VYPR
Unrated severityNVD Advisory· Published Dec 31, 2004· Updated Jun 16, 2026

CVE-2004-1452

CVE-2004-1452

Description

Tomcat before 5.0.27-r3 in Gentoo Linux sets the default permissions on the init scripts as tomcat:tomcat, but executes the scripts with root privileges, which could allow local users in the tomcat group to execute arbitrary commands as root by modifying the scripts.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

9
  • cpe:2.3:o:gentoo:linux:0.5:*:*:*:*:*:*:*+ 7 more
    • cpe:2.3:o:gentoo:linux:0.5:*:*:*:*:*:*:*
    • cpe:2.3:o:gentoo:linux:0.7:*:*:*:*:*:*:*
    • cpe:2.3:o:gentoo:linux:1.1a:*:*:*:*:*:*:*
    • cpe:2.3:o:gentoo:linux:1.2:*:*:*:*:*:*:*
    • cpe:2.3:o:gentoo:linux:1.4:*:*:*:*:*:*:*
    • cpe:2.3:o:gentoo:linux:1.4:rc1:*:*:*:*:*:*
    • cpe:2.3:o:gentoo:linux:1.4:rc2:*:*:*:*:*:*
    • cpe:2.3:o:gentoo:linux:1.4:rc3:*:*:*:*:*:*
  • Range: <5.0.27-r3

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.