Vulnerability Name: | CVE-2005-2693 (CCN-21983) | ||||||||||||||||||||
Assigned: | 2005-08-19 | ||||||||||||||||||||
Published: | 2005-08-19 | ||||||||||||||||||||
Updated: | 2017-10-11 | ||||||||||||||||||||
Summary: | cvsbug in CVS 1.12.12 and earlier creates temporary files insecurely, which allows local users to overwrite arbitrary files and execute arbitrary code via a symlink attack. | ||||||||||||||||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L)
| ||||||||||||||||||||
CVSS v2 Severity: | 4.6 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||||||||||
Vulnerability Consequences: | File Manipulation | ||||||||||||||||||||
References: | Source: CCN Type: FreeBSD Security Advisory FreeBSD-SA-05:20.cvsbug Race condition in cvsbug Source: FREEBSD Type: UNKNOWN FreeBSD-SA-05:20 Source: MITRE Type: CNA CVE-2005-2693 Source: CCN Type: RHSA-2005-756 cvs security update Source: SECUNIA Type: UNKNOWN 16765 Source: CCN Type: SECTRACK ID: 1014857 CVS Unsafe Temporary Files in `cvsbug` May Let Local Users Gain Elevated Privileges Source: SECTRACK Type: UNKNOWN 1014857 Source: CCN Type: CIAC INFORMATION BULLETIN P-299 'cvsbug' Security Update Source: CCN Type: Concurrent Versions System (CVS) CVS Home Source: DEBIAN Type: UNKNOWN DSA-802 Source: DEBIAN Type: UNKNOWN DSA-806 Source: DEBIAN Type: DSA-802 cvs -- insecure temporary files Source: DEBIAN Type: DSA-806 gcvs -- insecure temporary files Source: REDHAT Type: UNKNOWN RHSA-2005:756 Source: CCN Type: BID-14648 CVS Cvsbug.In Script Insecure Temporary File Creation Vulnerability Source: VUPEN Type: UNKNOWN ADV-2005-1667 Source: CONFIRM Type: Patch https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=166366 Source: XF Type: UNKNOWN cvs-cvsbug-symlink(21983) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:10835 | ||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Denotes that component is vulnerable | ||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||
| |||||||||||||||||||||
BACK |