PT-2005-1005 · Gnu · Gnump3D

Dabfus

·

Published

2005-11-18

·

Updated

2011-10-18

·

CVE-2005-3349

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Gnump3d versions prior to 2.9.8
Description The issue allows local users to modify or delete arbitrary files via a symlink attack on the index.lok temporary file. Additionally, there are multiple vulnerabilities in the gnump3d package that can lead to a breach of confidentiality and integrity of protected information, and these can be exploited remotely.
Recommendations For versions prior to 2.9.8, update to version 2.9.8 or later to resolve the issue. As a temporary workaround, consider restricting access to the index.lok temporary file to minimize the risk of exploitation.

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-01963
CVE-2005-3349
DSA-901-1

Affected Products

Gnump3D