PT-2005-4150 · Noweb · Noweb

Javier Fernandez-Sanguino

·

Published

2005-12-31

·

Updated

2011-03-08

·

CVE-2005-3342

CVSS v2.0

1.2

Low

VectorAV:L/AC:H/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions noweb versions 2.10c and earlier
Description The issue allows local users to overwrite arbitrary files via symlink attacks on temporary files in (1) lib/toascii.nw and (2) shell/roff.mm.
Recommendations For noweb versions 2.10c and earlier, consider updating to a version later than 2.10c to resolve the issue. As a temporary workaround, restrict access to the temporary files in lib/toascii.nw and shell/roff.mm to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-3342
DSA-968-1

Affected Products

Noweb