---
title: "CVE-2004-0966\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2004-0966?format=md
keywords: index, follow
---

# CVE-2004-0966

Publication date 9 February 2005

Last updated 17 July 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

The (1) autopoint and (2) gettextize scripts in the GNU gettext package
1.14 and later versions, as used in Trustix Secure Linux 1.5 through 2.1
and other operating systems, allows local users to overwrite files via a
symlink attack on temporary files.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| gettext | 7.04 feisty | Fixed 0.14.5-2ubuntu3 |
| 6.10 edgy | Fixed 0.14.5-2ubuntu3 |
| 6.06 LTS dapper | Fixed 0.14.5-2ubuntu3 |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2004-0966)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2004-0966)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2004-0966)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2004-0966)

### Related Ubuntu Security Notices (USN)

+ [USN-5-1](https://usn.ubuntu.com/USN-5-1)
+ gettext vulnerabilities
+ 27 October 2004

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2004-0966>
