First published: Wed Jul 06 2005(Updated: )
linki.py in ekg 2005-06-05 and earlier allows local users to overwrite or create arbitrary files via a symlink attack on temporary files.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
ekg ekg | <=2005-06-05 | |
Debian GNU/Linux | =3.1 | |
ekg | =2005-06-05 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-1916 is considered a moderate severity vulnerability as it allows local users to overwrite or create arbitrary files.
To fix CVE-2005-1916, update to a version of ekg released after June 5, 2005, or implement proper permissions to secure temporary files.
CVE-2005-1916 affects local users of ekg version 2005-06-05 and earlier, as well as users on Debian 3.1.
CVE-2005-1916 is associated with a symlink attack that exploits temporary file handling vulnerabilities.
No, CVE-2005-1916 cannot be exploited remotely as it requires local user access to take advantage of the vulnerability.