CVE-2005-2809: Low severity silc Secure Internet Live Conferencing vulnerability
silc daemon (silcd.c) in Secure Internet Live Conferencing (SILC) 1.0 and earlier allows local users to overwrite arbitrary files via a symlink attack on the silcd.[PID].stats temporary file.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-2809?
CVE-2005-2809 is classified as a moderate severity vulnerability due to its potential for local file overwrite.
How do I fix CVE-2005-2809?
To mitigate CVE-2005-2809, ensure that you update to the latest version of Secure Internet Live Conferencing that addresses this symlink vulnerability.
What systems are affected by CVE-2005-2809?
CVE-2005-2809 affects versions 1.0 and earlier of Secure Internet Live Conferencing (SILC), including multiple specific older versions.
Can CVE-2005-2809 be exploited remotely?
CVE-2005-2809 can only be exploited locally by users with access to the system where SILC is running.
What is a symlink attack in relation to CVE-2005-2809?
A symlink attack involving CVE-2005-2809 allows local users to create symbolic links that can redirect file writes to arbitrary locations on the filesystem.