PT-2006-1143 · Freebsd · Ee
Published
2006-01-11
·
Updated
2017-07-20
·
CVE-2006-0055
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
ee versions 4.10 through 6.0 on FreeBSD
Description:
The issue arises from the ispell op function in ee, which uses predictable filenames and does not confirm the file being written. This allows local users to overwrite arbitrary files via a symlink attack when ee invokes ispell.
Recommendations:
For ee versions 4.10 through 6.0 on FreeBSD, consider restricting access to the ispell op function until a patch is available. As a temporary workaround, avoid using the ispell functionality in ee to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ee