Vulnerability Name: | CVE-2005-3341 (CCN-23859) | ||||||||
Assigned: | 2005-12-27 | ||||||||
Published: | 2005-12-27 | ||||||||
Updated: | 2017-07-11 | ||||||||
Summary: | DHIS tools DNS package (dhis-tools-dns) before 5.0 allows local users to overwrite arbitrary files via a symlink attack on temporary files created by (1) register-q.sh and (2) register-p.sh. | ||||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | File Manipulation | ||||||||
References: | Source: MITRE Type: CNA CVE-2005-3341 Source: CCN Type: SA18227 DHIS Tools Insecure Temporary File Creation Source: SECUNIA Type: Vendor Advisory 18227 Source: SECUNIA Type: Patch, Vendor Advisory 18228 Source: DEBIAN Type: Patch, Vendor Advisory DSA-928 Source: DEBIAN Type: DSA-928 dhis-tools-dns -- insecure temporary file Source: CCN Type: DHIS Web site Introduction Source: OSVDB Type: UNKNOWN 21934 Source: OSVDB Type: UNKNOWN 21935 Source: CCN Type: OSVDB ID: 21934 DHIS Tools register-p.sh Symlink Arbitrary File Overwrite Source: CCN Type: OSVDB ID: 21935 DHIS Tools register-q.sh Symlink Arbitrary File Overwrite Source: BID Type: UNKNOWN 16065 Source: CCN Type: BID-16065 Debian DHIS-TOOLS-DNS Insecure Temporary File Creation Vulnerability Source: XF Type: UNKNOWN dhistools-temp-file-symlink(23859) Source: XF Type: UNKNOWN dhistools-temp-file-symlink(23859) | ||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |