CVE-2005-2180: Low severity GNU GNATS vulnerability
gen-index in GNATS 4.0, 4.1.0, and possibly earlier versions, when installed setuid, does not properly check files passed to the -o argument and opens the file with write access, which allows local users to overwrite arbitrary files.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2005-2180?
CVE-2005-2180 is considered a high severity vulnerability due to its potential for local users to overwrite arbitrary files.
How do I fix CVE-2005-2180?
To fix CVE-2005-2180, you should remove the setuid bit from the gen-index binary or upgrade to a patched version of GNATS.
What versions of GNATS are affected by CVE-2005-2180?
CVE-2005-2180 affects GNU GNATS versions 4.0, 4.1.0, and possibly earlier versions.
Who can exploit CVE-2005-2180?
Local users who have access to the system can exploit CVE-2005-2180 due to its nature of allowing unauthorized file overwriting.
What is the impact of CVE-2005-2180?
The impact of CVE-2005-2180 includes the potential for local users to overwrite important system files, leading to data loss or system instability.