Vulnerability Name: | CVE-2005-1740 (CCN-20763) | ||||||||||||||||
Assigned: | 2005-05-18 | ||||||||||||||||
Published: | 2005-05-18 | ||||||||||||||||
Updated: | 2017-10-11 | ||||||||||||||||
Summary: | fixproc in Net-snmp 5.x before 5.2.1-r1 creates temporary files insecurely, which allows local users to modify the contents of those files to execute arbitrary commands, or overwrite arbitrary files via a symlink attack. | ||||||||||||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L)
| ||||||||||||||||
CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C) 8.7 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:H/RL:OF/RC:C)
2.3 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:H/Au:N/C:N/I:P/A:P/E:H/RL:OF/RC:C)
| ||||||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||||||
Vulnerability Consequences: | File Manipulation | ||||||||||||||||
References: | Source: CCN Type: Sun Security Blog Aug 16, 2011 CVE-2005-1740 Vulnerability in Net-snmp Source: MITRE Type: CNA CVE-2005-1740 Source: CCN Type: Net-SNMP Web site Net-SNMP Source: CCN Type: RHSA-2005-373 net-snmp security update Source: CCN Type: RHSA-2005-395 net-snmp security update Source: CCN Type: SA15471 Net-snmp fixproc Insecure Temporary File Creation Source: SECUNIA Type: UNKNOWN 15471 Source: SECUNIA Type: UNKNOWN 16999 Source: SECUNIA Type: UNKNOWN 17135 Source: SECUNIA Type: UNKNOWN 18635 Source: CCN Type: SA45609 Oracle Solaris Net-snmp fixproc Insecure Temporary File Creation Vulnerability Source: GENTOO Type: Vendor Advisory GLSA-200505-18 Source: CCN Type: SECTRACK ID: 1014039 net-snmp `fixproc` Unsafe Temporary File Lets Local Users Gain Elevated Privileges Source: SECTRACK Type: UNKNOWN 1014039 Source: CCN Type: GLSA-200505-18 Net-SNMP: fixproc insecure temporary file creation Source: MANDRIVA Type: UNKNOWN MDKSA-2006:025 Source: OSVDB Type: UNKNOWN 16778 Source: CCN Type: OSVDB ID: 16778 Net-SNMP fixproc Temporary File Local Privilege Escalation Source: REDHAT Type: UNKNOWN RHSA-2005:373 Source: REDHAT Type: UNKNOWN RHSA-2005:395 Source: BID Type: UNKNOWN 13715 Source: CCN Type: BID-13715 Net-SNMP Fixproc Insecure Temporary File Creation Vulnerability Source: VUPEN Type: UNKNOWN ADV-2005-0598 Source: MISC Type: UNKNOWN http://www.zataz.net/adviso/net-snmp-05182005.txt Source: XF Type: UNKNOWN netsnmp-fixproc-symlink(20763) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:11659 | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: ![]() | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |