PT-2005-4150 · Noweb · Noweb
Javier Fernandez-Sanguino
·
Published
2005-12-31
·
Updated
2011-03-08
·
CVE-2005-3342
CVSS v2.0
1.2
Low
| Vector | AV:L/AC:H/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
noweb versions 2.10c and earlier
Description
The issue allows local users to overwrite arbitrary files via symlink attacks on temporary files in (1) lib/toascii.nw and (2) shell/roff.mm.
Recommendations
For noweb versions 2.10c and earlier, consider updating to a version later than 2.10c to resolve the issue. As a temporary workaround, restrict access to the temporary files in lib/toascii.nw and shell/roff.mm to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Noweb