CVE-2005-2991: Low severity ncompress ncompress vulnerability
Published Sep 20, 2005
·Updated
ncompress 4.2.4 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files using (1) zdiff or (2) zcmp, a different vulnerability than CVE-2004-0970.
Affected Software
1 affected component
ncompress ncompress<=4.2.4_r1
Event History
Sep 20, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-2991?
CVE-2005-2991 is classified as a moderate severity vulnerability due to the potential for local file overwrites.
2
How do I fix CVE-2005-2991?
To mitigate CVE-2005-2991, update to a version of ncompress later than 4.2.4.
3
Who is affected by CVE-2005-2991?
Local users on systems running ncompress version 4.2.4 or earlier are affected by CVE-2005-2991.
4
What type of attack does CVE-2005-2991 involve?
CVE-2005-2991 involves a symlink attack that allows for unauthorized file overwrites.
5
Which applications are associated with CVE-2005-2991?
CVE-2005-2991 is specifically associated with the ncompress application, particularly versions up to 4.2.4.