Secunia Logo
 
CVE Reference: CVE-2005-2672
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2005-2672

Description:
pwmconfig in LM_sensors before 2.9.1 creates temporary files insecurely, which allows local users to overwrite arbitrary files via a symlink attack on the fancontrol temporary file.

CVE Status:
Candidate

References:

UBUNTU
  http://www.ubuntulinux.org/support/documentation/usn/usn-172-1

ST
  1015180

SAID
  Secunia Advisory: SA16501
  Secunia Advisory: SA17499
  Secunia Advisory: SA17535

REDHAT
  http://www.redhat.com/support/errata/RHSA-2005-825.html

MANDRIVA
  http://www.mandriva.com/security/advisories?name=MDKSA-2005:149

DEBIAN
  http://www.debian.org/security/2005/dsa-814

CONFIRM
  http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=324193
  http://secure.netroedge.com/~lm78/cvs/lm_sensors2/CHANGES

BID
  14624


Return to the previous page.