PT-2005-5598 · Debian · Cfengine
Javier Fernández-Sanguino Peña
·
Publicado
1970-01-01
·
Atualizado
2017-07-11
·
CVE-2005-3137
CVSS v2.0
2.1
Baixa
| Vetor | AV:L/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
cfengine version 1.6.5
Description
The issue concerns multiple vulnerabilities in the cfengine package of the Debian GNU/Linux operating system, which can be exploited by a local attacker to compromise the integrity of protected information. Specifically, the cfmailfilter and cfcron.in files for cfengine 1.6.5 are vulnerable to a symlink attack on temporary files, allowing local users to overwrite arbitrary files.
Recommendations
For version 1.6.5, consider restricting access to the cfmailfilter and cfcron.in files to prevent local users from exploiting the vulnerability. As a temporary workaround, consider disabling the
cfmailfilter and cfcron.in files until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability. Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Cfengine