CVE-2005-0077: Low severity redhat Enterprise Linux vulnerability
Published Jan 29, 2005
·Updated
The DBI library (libdbi-perl) for Perl allows local users to overwrite arbitrary files via a symlink attack on a temporary PID file.
Affected Software
7 affected components
redhat Enterprise Linux=4.0
redhat Enterprise Linux=4.0
Ubuntu Ubuntu Linux=4.10
Debian Debian Linux=3.0
redhat Enterprise Linux=4.0
redhat Enterprise Linux Desktop=4.0
Gentoo Linux
Remediation
Patch Available
Patch Available
Patch Available
Event History
Jan 29, 2005
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-0077?
CVE-2005-0077 is considered a moderate severity vulnerability due to the potential for local users to overwrite arbitrary files.
2
How do I fix CVE-2005-0077?
To fix CVE-2005-0077, ensure that all instances of the DBI library are updated to the patched versions provided by your Linux distribution.
3
What systems are affected by CVE-2005-0077?
CVE-2005-0077 affects multiple systems including Red Hat Enterprise Linux 4.0, Ubuntu Linux 4.10, and Debian Linux 3.0.
4
Can a remote attacker exploit CVE-2005-0077?
No, CVE-2005-0077 requires local access to exploit the vulnerability.
5
What is a symlink attack in the context of CVE-2005-0077?
A symlink attack in CVE-2005-0077 refers to exploiting the insecure handling of temporary PID files to overwrite arbitrary files.