Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Javier Fernandez-Sanguino

#52869de 53,635
3.3CVSS total
Vulnerabilidades · 2
Baixa
2
PT-2005-4150
1.2
2005-12-31
Noweb · Noweb · CVE-2005-3342
**Name of the Vulnerable Software and Affected Versions** noweb versions 2.10c and earlier **Description** The issue allows local users to overwrite arbitrary files via symlink attacks on temporary files in (1) lib/toascii.nw and (2) shell/roff.mm. **Recommendations** For noweb versions 2.10c and earlier, consider updating to a version later than 2.10c to resolve the issue. As a temporary workaround, restrict access to the temporary files in lib/toascii.nw and shell/roff.mm to minimize the risk of exploitation.
PT-2005-3899
2.1
2005-09-27
Hylafax · Hylafax · CVE-2005-3069
**Name of the Vulnerable Software and Affected Versions** HylaFax versions 4.2.1 and earlier **Description** The issue allows local users to overwrite arbitrary files via a symlink attack on the xferfax$$ temporary file. This is related to the `xferfaxstats` component in HylaFax. **Recommendations** For HylaFax versions 4.2.1 and earlier, consider restricting access to the `xferfaxstats` component until a patch is available. As a temporary workaround, avoid using the `xferfaxstats` command to prevent potential exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.