PT-2005-1042 · Gtk+ · Gtkdiskfree
Eric Romang
·
Publicado
2005-09-15
·
Atualizado
2016-10-18
·
CVE-2005-2918
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
gtkdiskfree version 1.9.3 and earlier
Description
The issue allows local users to overwrite arbitrary files via a symlink attack on the gtkdiskfree temporary file, potentially leading to data integrity violations. Additionally, there are multiple vulnerabilities in the gtkdiskfree package that can be exploited remotely, compromising the integrity of protected information.
Recommendations
For gtkdiskfree version 1.9.3 and earlier, consider restricting access to the
open cmd tube function in mount.c until a patch is available. As a temporary workaround, avoid using the open cmd tube function to minimize the risk of exploitation.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Gtkdiskfree