PT-2005-1257 · Unknown · Toolchain-Source

Sean Finney

·

Publicado

2005-02-15

·

Atualizado

2017-07-11

·

CVE-2005-0159

CVSS v2.0

4.6

Média

VetorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions toolchain-source version 3.0.4
Description The issue allows local users to overwrite arbitrary files via a symlink attack on temporary files created by the tpkg-* scripts.
Recommendations For toolchain-source version 3.0.4, consider restricting access to the tpkg-* scripts until a patch is available to prevent local users from overwriting arbitrary files.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-0159
DSA-679-1

Produtos afetados

Toolchain-Source