Vulnerability Name: | CVE-2005-1751 (CCN-20778) | ||||||||||||||||||||
Assigned: | 2005-05-24 | ||||||||||||||||||||
Published: | 2005-05-24 | ||||||||||||||||||||
Updated: | 2018-05-03 | ||||||||||||||||||||
Summary: | Race condition in shtool 2.0.1 and earlier allows local users to create or modify arbitrary files via a symlink attack on the .shtool.$$ temporary file, a different vulnerability than CVE-2005-1759. | ||||||||||||||||||||
CVSS v3 Severity: | 4.9 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||||||||||
CVSS v2 Severity: | 3.7 Low (CVSS v2 Vector: AV:L/AC:H/Au:N/C:P/I:P/A:P)
| ||||||||||||||||||||
Vulnerability Type: | CWE-Other CWE-377 | ||||||||||||||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||||||||||||||
References: | Source: MISC Type: UNKNOWN http://bugs.gentoo.org/show_bug.cgi?id=93782 Source: MITRE Type: CNA CVE-2005-1751 Source: MITRE Type: CNA CVE-2005-1759 Source: OPENPKG Type: UNKNOWN OpenPKG-SA-2005.011 Source: CCN Type: BugTraq Mailing List, 2005-05-25 17:44:40 shtool insecure temporary file creation Source: CCN Type: RHSA-2005-564 php security update Source: CCN Type: SA15496 GNU shtool Insecure Temporary File Creation Source: SECUNIA Type: UNKNOWN 15496 Source: SECUNIA Type: UNKNOWN 15668 Source: CCN Type: SECTRACK ID: 1014059 shtool Temporary File May Let Local users gain Elevated Privileges Source: SECTRACK Type: UNKNOWN 1014059 Source: DEBIAN Type: UNKNOWN DSA-789 Source: DEBIAN Type: DSA-789 php4 -- several vulnerabilities Source: CCN Type: GLSA-200506-08 GNU shtool, ocaml-mysql: Insecure temporary file creation Source: GENTOO Type: UNKNOWN GLSA-200506-08 Source: CCN Type: shtool Web site GNU shtool - GNU Project - Free Software Foundation (FSF) Source: CCN Type: OpenPKG-SA-2005.011 GNU shtool Source: CCN Type: OSVDB ID: 17289 shtool Reused Temp Files Symlink Arbitrary File Overwrite Source: CCN Type: PHP Web site PHP: Hypertext Preprocessor Source: REDHAT Type: UNKNOWN RHSA-2005:564 Source: BID Type: UNKNOWN 13767 Source: CCN Type: BID-13767 GNU SHTool Insecure Temporary File Deletion Vulnerability Source: CCN Type: USN-171-1 PHP4 vulnerabilities Source: MISC Type: Vendor Advisory http://www.zataz.net/adviso/shtool-05252005.txt Source: XF Type: UNKNOWN shtool-race-condition(20778) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:345 Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:9639 | ||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: ![]() | ||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||
| |||||||||||||||||||||
BACK |