Secunia Logo
 
CVE Reference: CVE-2005-2960
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2005-2960

Description:
cfengine 1.6.5 and 2.1.16 allows local users to overwrite arbitrary files via a symlink attack on temporary files used by vicf.in, a different vulnerability than CVE-2005-3137.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/22489

UBUNTU
  http://www.ubuntu.com/usn/usn-198-1

SUSE
  http://www.novell.com/linux/security/advisories/2005_23_sr.html

SAID
  Secunia Advisory: SA17215
  Secunia Advisory: SA17142
  Secunia Advisory: SA17182
  Secunia Advisory: SA17038
  Secunia Advisory: SA17040
  Secunia Advisory: SA17037

MISC
  http://groups.google.com/group/gnu.cfengine.help/browse_thread/thread/fc25e7d98f8ba401/38151ed821803be0#38151ed821803be0
  http://bugs.gentoo.org/show_bug.cgi?id=107871

MANDRIVA
  http://frontal2.mandriva.com/security/advisories?name=MDKSA-2005:184

DEBIAN
  http://www.debian.org/security/2005/dsa-835
  http://www.debian.org/security/2005/dsa-836

BID
  14994


Return to the previous page.