PT-2006-1143 · Freebsd · Ee
Publicado
2006-01-11
·
Atualizado
2017-07-20
·
CVE-2006-0055
CVSS v2.0
2.1
Baixa
| Vetor | AV:L/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
ee versions 4.10 through 6.0 on FreeBSD
Description:
The issue arises from the ispell op function in ee, which uses predictable filenames and does not confirm the file being written. This allows local users to overwrite arbitrary files via a symlink attack when ee invokes ispell.
Recommendations:
For ee versions 4.10 through 6.0 on FreeBSD, consider restricting access to the ispell op function until a patch is available. As a temporary workaround, avoid using the ispell functionality in ee to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Ee