Lucene search

K
cveMitreCVE-2006-1695
HistoryApr 11, 2006 - 10:02 a.m.

CVE-2006-1695

2006-04-1110:02:00
mitre
web.nvd.nist.gov
26
fbgs script
fbi package
local users
symlink attack
temporary files
security vulnerability

CVSS2

1.2

Attack Vector

LOCAL

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:H/Au:N/C:N/I:P/A:N

AI Score

5.9

Confidence

Low

EPSS

0

Percentile

5.1%

The fbgs script in the fbi package 2.01-1.4, when the TMPDIR environment variable is not defined, allows local users to overwrite arbitrary files via a symlink attack on temporary files in /var/tmp/fbps-[PID].

Affected configurations

Nvd
Node
fbidafbidaMatch2.01
OR
fbidafbidaMatch2.02
OR
fbidafbidaMatch2.03
VendorProductVersionCPE
fbidafbida2.01cpe:2.3:a:fbida:fbida:2.01:*:*:*:*:*:*:*
fbidafbida2.02cpe:2.3:a:fbida:fbida:2.02:*:*:*:*:*:*:*
fbidafbida2.03cpe:2.3:a:fbida:fbida:2.03:*:*:*:*:*:*:*

CVSS2

1.2

Attack Vector

LOCAL

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:H/Au:N/C:N/I:P/A:N

AI Score

5.9

Confidence

Low

EPSS

0

Percentile

5.1%