First published: Tue Sep 20 2005(Updated: )
ncompress 4.2.4 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files using (1) zdiff or (2) zcmp, a different vulnerability than CVE-2004-0970.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
SUSE Ncompress | <=4.2.4_r1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2991 is classified as a moderate severity vulnerability due to the potential for local file overwrites.
To mitigate CVE-2005-2991, update to a version of ncompress later than 4.2.4.
Local users on systems running ncompress version 4.2.4 or earlier are affected by CVE-2005-2991.
CVE-2005-2991 involves a symlink attack that allows for unauthorized file overwrites.
CVE-2005-2991 is specifically associated with the ncompress application, particularly versions up to 4.2.4.