CVE-2005-1270: Low severity Gentoo Rootkit Hunter vulnerability
Published Apr 26, 2005
·Updated
The (1) checkupdate.sh and (2) rkhunter script in Rootkit Hunter before 1.2.3-r1 create temporary files with predictable file names, which allows local users to overwrite arbitrary files via a symlink attack.
Affected Software
4 affected components
Gentoo Rootkit Hunter=1.2.1
Gentoo Rootkit Hunter=1.2.3
Gentoo Rootkit Hunter=1.2
Gentoo Rootkit Hunter=1.2.2
Remediation
Patch Available
Patch Available
Event History
Apr 26, 2005
CVE Published
04:00 AM
Apr 28, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-1270?
CVE-2005-1270 has a medium severity level due to its potential for local file overwriting via a symlink attack.
2
How do I fix CVE-2005-1270?
To fix CVE-2005-1270, upgrade to Rootkit Hunter version 1.2.3-r1 or later.
3
Which versions of Rootkit Hunter are affected by CVE-2005-1270?
CVE-2005-1270 affects Rootkit Hunter versions 1.2, 1.2.1, 1.2.2, and 1.2.3.
4
What are the risks associated with CVE-2005-1270?
The risks associated with CVE-2005-1270 include unauthorized file modification and a potential compromise of system integrity.
5
How does CVE-2005-1270 exploit the system?
CVE-2005-1270 exploits the system by allowing local users to perform a symlink attack to overwrite arbitrary files.