PT-2005-4150 · Noweb · Noweb

Javier Fernandez-Sanguino

·

Publicado

2005-12-31

·

Atualizado

2011-03-08

·

CVE-2005-3342

CVSS v2.0

1.2

Baixa

VetorAV:L/AC:H/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions noweb versions 2.10c and earlier
Description The issue allows local users to overwrite arbitrary files via symlink attacks on temporary files in (1) lib/toascii.nw and (2) shell/roff.mm.
Recommendations For noweb versions 2.10c and earlier, consider updating to a version later than 2.10c to resolve the issue. As a temporary workaround, restrict access to the temporary files in lib/toascii.nw and shell/roff.mm to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-3342
DSA-968-1

Produtos afetados

Noweb