PT-2005-3686 · Secure Internet Live Conferencing · Silc

Romang

·

Publicado

2005-09-07

·

Atualizado

2008-09-05

·

CVE-2005-2809

CVSS v2.0

2.1

Baixa

VetorAV:L/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions SILC versions 1.0 and earlier
Description The issue allows local users to overwrite arbitrary files via a symlink attack on the silcd.[PID].stats temporary file. This is due to a flaw in the silc daemon (silcd.c) in Secure Internet Live Conferencing (SILC).
Recommendations For SILC versions 1.0 and earlier, consider restricting access to the silc daemon to prevent local users from exploiting this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-2809

Produtos afetados

Silc