PT-2005-1257 · Unknown · Toolchain-Source

Sean Finney

·

Published

2005-02-15

·

Updated

2017-07-11

·

CVE-2005-0159

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions toolchain-source version 3.0.4
Description The issue allows local users to overwrite arbitrary files via a symlink attack on temporary files created by the tpkg-* scripts.
Recommendations For toolchain-source version 3.0.4, consider restricting access to the tpkg-* scripts until a patch is available to prevent local users from overwriting arbitrary files.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-0159
DSA-679-1

Affected Products

Toolchain-Source