Vulnerability Name:

CVE-2005-2180 (CCN-23228)

Assigned:2005-06-16
Published:2005-06-16
Updated:2016-10-18
Summary:gen-index in GNATS 4.0, 4.1.0, and possibly earlier versions, when installed setuid, does not properly check files passed to the -o argument and opens the file with write access, which allows local users to overwrite arbitrary files.
CVSS v3 Severity:4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
2.1 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-Other
Vulnerability Consequences:File Manipulation
References:Source: MITRE
Type: CNA
CVE-2005-2180

Source: BUGTRAQ
Type: UNKNOWN
20050706 GNATS - gen-index

Source: CCN
Type: BugTraq Mailing List, 2005-07-06 15:03:23
GNATS - gen-index

Source: CCN
Type: SA15963
GNATS Arbitrary File Overwrite Security Issue

Source: SECUNIA
Type: UNKNOWN
15963

Source: CCN
Type: GNATS Web page
GNATS - GNU Project - Free Software Foundation (FSF)

Source: CCN
Type: OSVDB ID: 17759
GNATS gen-index -o Parameter Arbitrary File Overwrite

Source: MISC
Type: UNKNOWN
http://www.pi3.int.pl/adv/gnats.txt

Source: CCN
Type: BID-14169
GNU GNATS Gen-Index Arbitrary Local File Disclosure/Overwrite Vulnerability

Source: XF
Type: UNKNOWN
gnats-o-file-overwrite(23228)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:gnu:gnats:4.0:*:*:*:*:*:*:*
  • OR cpe:/a:gnu:gnats:4.1.0:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:gnu:gnats:4.0:*:*:*:*:*:*:*
  • OR cpe:/a:gnu:gnats:4.1.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    gnu gnats 4.0
    gnu gnats 4.1.0
    gnu gnats 4.0
    gnu gnats 4.1.0