PT-2005-5598 · Debian · Cfengine
Javier Fernández-Sanguino Peña
·
Published
1970-01-01
·
Updated
2017-07-11
·
CVE-2005-3137
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
cfengine version 1.6.5
Description
The issue concerns multiple vulnerabilities in the cfengine package of the Debian GNU/Linux operating system, which can be exploited by a local attacker to compromise the integrity of protected information. Specifically, the cfmailfilter and cfcron.in files for cfengine 1.6.5 are vulnerable to a symlink attack on temporary files, allowing local users to overwrite arbitrary files.
Recommendations
For version 1.6.5, consider restricting access to the cfmailfilter and cfcron.in files to prevent local users from exploiting the vulnerability. As a temporary workaround, consider disabling the
cfmailfilter and cfcron.in files until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability. Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cfengine