CVE-2005-2960: Low severity GNU CFEngine vulnerability
cfengine 1.6.5 and 2.1.16 allows local users to overwrite arbitrary files via a symlink attack on temporary files used by vicf.in, a different vulnerability than CVE-2005-3137.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-2960?
The severity of CVE-2005-2960 is considered moderate due to the potential for a symlink attack that allows local users to overwrite arbitrary files.
How do I fix CVE-2005-2960?
To fix CVE-2005-2960, you should update to a version of GNU CFEngine that is not vulnerable, specifically later versions beyond 2.1.16.
Which versions of CFEngine are affected by CVE-2005-2960?
CVE-2005-2960 affects CFEngine versions 1.6.5, 2.0.5, 2.0.7, 2.0.8, and 2.1.16, among others.
Can CVE-2005-2960 be exploited remotely?
CVE-2005-2960 cannot be exploited remotely as it requires local user access to perform the symlink attack.
What type of vulnerability is CVE-2005-2960 classified as?
CVE-2005-2960 is classified as a file overwrite vulnerability due to improper handling of temporary files.