Lucene search

K
cve[email protected]CVE-2005-4691
HistoryOct 03, 2022 - 4:22 p.m.

CVE-2005-4691

2022-10-0316:22:44
web.nvd.nist.gov
24
vulnerability
cve-2005-4691
netbsd
x.org
xfree86
symlink attack
file overwrite

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:L/Au:N/C:N/I:P/A:N

6.8 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

imake in NetBSD before 2.0.3, NetBSD-current before 12 September 2005, certain versions of X.Org, and certain versions of XFree86 allows local users to overwrite arbitrary files via a symlink attack on the temporary file for the file.0 target, which is used for a pre-formatted manual page.

Affected configurations

NVD
Node
netbsdnetbsdMatch1.6
OR
netbsdnetbsdMatch1.6beta
OR
netbsdnetbsdMatch1.6.1
OR
netbsdnetbsdMatch1.6.2
OR
netbsdnetbsdMatch2.0
OR
netbsdnetbsdMatch2.0.1
OR
netbsdnetbsdMatch2.0.2

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:L/Au:N/C:N/I:P/A:N

6.8 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

5.1%

Related for CVE-2005-4691