PT-2006-1143 · Freebsd · Ee

Published

2006-01-11

·

Updated

2017-07-20

·

CVE-2006-0055

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: ee versions 4.10 through 6.0 on FreeBSD
Description: The issue arises from the ispell op function in ee, which uses predictable filenames and does not confirm the file being written. This allows local users to overwrite arbitrary files via a symlink attack when ee invokes ispell.
Recommendations: For ee versions 4.10 through 6.0 on FreeBSD, consider restricting access to the ispell op function until a patch is available. As a temporary workaround, avoid using the ispell functionality in ee to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-0055

Affected Products

Ee