First published: Tue May 24 2005(Updated: )
The fn_show_postinst function in Gentoo webapp-config before 1.10-r14 allows local users to overwrite arbitrary files via a symlink attack on the postinst.txt temporary file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Gentoo Linux Webapp-config | =1.10-r14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-1707 has been classified as a medium severity vulnerability.
To fix CVE-2005-1707, update the Gentoo webapp-config package to version 1.10-r14 or later.
CVE-2005-1707 allows local users to perform symlink attacks that can lead to file overwriting.
CVE-2005-1707 affects Gentoo Linux webapp-config versions prior to 1.10-r14.
CVE-2005-1707 is a local vulnerability, requiring access to the system to exploit.