Vulnerability Name: | CVE-2005-0069 (CCN-18870) | ||||||||||||||||
Assigned: | 2005-01-09 | ||||||||||||||||
Published: | 2005-01-09 | ||||||||||||||||
Updated: | 2017-10-11 | ||||||||||||||||
Summary: | The (1) tcltags or (2) vimspell.sh scripts in vim 6.3 allow local users to overwrite or create arbitrary files via a symlink attack on temporary files. | ||||||||||||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L)
| ||||||||||||||||
CVSS v2 Severity: | 4.6 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||||||
Vulnerability Consequences: | File Manipulation | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2005-0069 Source: BUGTRAQ Type: UNKNOWN 20050118 [USN-61-1] vim vulnerabilities Source: CCN Type: RHSA-2005-036 vim security update Source: CCN Type: RHSA-2005-122 vim security update Source: CCN Type: SA13841 vim Insecure Temporary File Creation Source: SECUNIA Type: Patch, Vendor Advisory 13841 Source: CCN Type: SECTRACK ID: 1012938 Vim `tcltags` and `vimspell.sh` Temporary Files May Let Local Users Gain Elevated Privileges Source: SECTRACK Type: UNKNOWN 1012938 Source: REDHAT Type: Patch, Vendor Advisory RHSA-2005:036 Source: REDHAT Type: Patch, Vendor Advisory RHSA-2005:122 Source: CCN Type: BID-12253 Vim TCLTags and VimSpell.sh Scripts Insecure Temporary File Creation Vulnerability Source: CCN Type: USN-61-1 vim vulnerabilities Source: CCN Type: Vim Web site Vim Source: FEDORA Type: Vendor Advisory FLSA:2343 Source: XF Type: UNKNOWN vim-symlink(18870) Source: XF Type: UNKNOWN vim-symlink(18870) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:9402 | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |