| Vulnerability Name: | CVE-2005-3355 (CCN-23117) | ||||||||||||
| Assigned: | 2005-11-18 | ||||||||||||
| Published: | 2005-11-18 | ||||||||||||
| Updated: | 2011-10-18 | ||||||||||||
| Summary: | Directory traversal vulnerability in GNU Gnump3d before 2.9.8 has unknown impact via "CGI parameters, and cookie values". | ||||||||||||
| CVSS v3 Severity: | 6.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
| ||||||||||||
| CVSS v2 Severity: | 6.4 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N)
| ||||||||||||
| Vulnerability Type: | CWE-22 | ||||||||||||
| Vulnerability Consequences: | Obtain Information | ||||||||||||
| References: | Source: MITRE Type: CNA CVE-2005-3355 Source: CCN Type: gnump3d Web site Debian -- gnump3d Source: SECUNIA Type: Patch, Vendor Advisory 17646 Source: CCN Type: SA17647 GNUMP3d Insecure Temporary File Creation and Directory Traversal Source: SECUNIA Type: Patch, Vendor Advisory 17647 Source: SECUNIA Type: Patch, Vendor Advisory 17656 Source: DEBIAN Type: Patch DSA-901 Source: DEBIAN Type: DSA-901 gnump3d -- programming error Source: CCN Type: GLSA-200511-16 GNUMP3d: Directory traversal and insecure temporary file creation Source: GENTOO Type: Patch GLSA-200511-16 Source: CONFIRM Type: UNKNOWN http://www.gnu.org/software/gnump3d/ChangeLog Source: SUSE Type: Patch, Vendor Advisory SUSE-SR:2005:028 Source: CCN Type: OSVDB ID: 20940 GNUMP3d Cookie Value Unspecified Traversal Source: BID Type: Patch 15496 Source: CCN Type: BID-15496 GNU gnump3d CGI And Cookie Parameter Directory Traversal Vulnerability Source: VUPEN Type: Vendor Advisory ADV-2005-2489 Source: XF Type: UNKNOWN gnump3d-cgi-cookie-directory-traversal(23117) Source: SUSE Type: SUSE-SR:2005:028 SUSE Security Summary Report | ||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
| Oval Definitions | |||||||||||||
| |||||||||||||
| BACK | |||||||||||||