PT-2005-2809 · Adobe+1 · Creative Suite+3
Publicado
2005-08-24
·
Atualizado
2008-09-05
·
CVE-2005-1842
CVSS v2.0
2.1
Baixa
| Vetor | AV:L/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
VCNative for Adobe Version Cue versions 1.0 through 1.0.1
Description
The issue allows local users to modify arbitrary files via a symlink attack, as VCNative for Adobe Version Cue creates temporary log files with predictable names. This can be exploited when running on Mac OS X with Version Cue Workspace, as used in Creative Suite 1.0 and 1.3.
Recommendations
For VCNative for Adobe Version Cue versions 1.0 through 1.0.1, consider restricting access to the temporary log files to prevent a symlink attack until a patch is available. As a temporary workaround, avoid using the predictable naming scheme for temporary log files.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Creative Suite
Macos X
Vcnative For Adobe Version Cue
Version Cue Workspace