Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2005-3137
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2005-3137

Description:
The (1) cfmailfilter and (2) cfcron.in files for cfengine 1.6.5 allow local users to overwrite arbitrary files via a symlink attack on temporary files, a different vulnerability than CVE-2005-2960.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/22489

UBUNTU
  http://www.ubuntu.com/usn/usn-198-1

SAID
  Secunia Advisory: SA17142
  Secunia Advisory: SA17038
  Secunia Advisory: SA17040
  Secunia Advisory: SA17037
  Secunia Advisory: SA17182

MISC
  http://groups.google.com/group/gnu.cfengine.help/browse_thread/thread/fc25e7d98f8ba401/38151ed821803be0#38151ed821803be0
  http://bugs.gentoo.org/show_bug.cgi?id=107871

MANDRIVA
  http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:184

DEBIAN
  http://www.debian.org/security/2005/dsa-835
  http://www.debian.org/security/2005/dsa-836

BID
  14994


Return to the previous page.