CVE-2005-0610: High severity FreeBSD FreeBSD vulnerability
Multiple symlink vulnerabilities in portupgrade before 200412262 in FreeBSD allow local users to (1) overwrite arbitrary files and possibly replace packages to execute arbitrary code via pkgfetch, (2) overwrite arbitrary files via temporary files when portupgrade upgrades a port or package, or (3) create arbitrary zero-byte files via the pkgdb.fixme temporary file.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-0610?
CVE-2005-0610 is classified as a high severity vulnerability due to its potential to allow arbitrary file overwrites and execution of arbitrary code.
How do I fix CVE-2005-0610?
To remediate CVE-2005-0610, it is recommended to update to the latest version of portupgrade that includes the necessary security patches.
Who is affected by CVE-2005-0610?
CVE-2005-0610 affects local users of FreeBSD systems running vulnerable versions of portupgrade.
What types of attacks can CVE-2005-0610 facilitate?
CVE-2005-0610 may facilitate attacks that allow local users to overwrite arbitrary files or replace packages, leading to potential system compromise.
Are multiple versions of FreeBSD impacted by CVE-2005-0610?
Yes, CVE-2005-0610 affects several versions of FreeBSD, including 4.0 to 5.4, particularly those prior to the patch release.