PT-2006-7586 · Suse+1 · Suse Linux Enterprise+18
Sebastian Krahmer
·
Published
1970-01-01
·
Updated
2017-07-20
·
CVE-2006-5072
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
mono (affected versions not specified)
mono-core (affected versions not specified)
mono-core-32bit (affected versions not specified)
mono-core-x86 (affected versions not specified)
mono-data (affected versions not specified)
mono-data-sqlite (affected versions not specified)
mono-data-sybase (affected versions not specified)
mono-devel (affected versions not specified)
mono-extras (affected versions not specified)
mono-ikvm (affected versions not specified)
mono-jscript (affected versions not specified)
mono-locale-extras (affected versions not specified)
mono-nunit (affected versions not specified)
mono-web (affected versions not specified)
mono-winforms (affected versions not specified)
bytefx-data-mysql (affected versions not specified)
mono-basic (affected versions not specified)
Description
The issue affects multiple packages of the mono operating system, including SUSE Linux Enterprise and openSUSE, allowing for remote exploitation. This can lead to a breach of confidentiality, integrity, and availability of protected information. The System.CodeDom.Compiler classes in Novell Mono create temporary files with insecure permissions, enabling local users to overwrite arbitrary files or execute arbitrary code via a symlink attack.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Suse Linux Enterprise
Bytefx-Data-Mysql
Mono
Mono-Basic
Mono-Core
Mono-Core-32Bit
Mono-Core-X86
Mono-Data
Mono-Data-Sqlite
Mono-Data-Sybase
Mono-Devel
Mono-Extras
Mono-Ikvm
Mono-Jscript
Mono-Locale-Extras
Mono-Nunit
Mono-Web
Mono-Winforms
Opensuse