Lucene search

K
ubuntuUbuntuUSN-194-1
HistoryOct 06, 2005 - 12:00 a.m.

texinfo vulnerability

2005-10-0600:00:00
ubuntu.com
29

CVSS2

1.2

Attack Vector

LOCAL

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:H/Au:N/C:N/I:P/A:N

AI Score

6.3

Confidence

Low

EPSS

0.001

Percentile

28.0%

Releases

  • Ubuntu 5.04
  • Ubuntu 4.10

Details

Frank Lichtenheld discovered that the “texindex” program created
temporary files in an insecure manner. This could allow a symlink
attack to create or overwrite arbitrary files with the privileges of
the user running texindex.

OSVersionArchitecturePackageVersionFilename
Ubuntu5.04noarchtexinfo< *UNKNOWN
Ubuntu4.10noarchtexinfo< *UNKNOWN

CVSS2

1.2

Attack Vector

LOCAL

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:H/Au:N/C:N/I:P/A:N

AI Score

6.3

Confidence

Low

EPSS

0.001

Percentile

28.0%