First published: Wed Sep 21 2005(Updated: )
The sort_offline function for texindex in texinfo 4.8 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Gnu Texinfo | <=4.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-3011 describes a vulnerability in the sort_offline function of texindex in texinfo 4.8 and earlier, which allows local users to perform a symlink attack and overwrite arbitrary files.
CVE-2005-3011 affects all versions of Gnu Texinfo up to and including version 4.8.
To mitigate CVE-2005-3011, avoid using vulnerable versions of texinfo and upgrade to a fixed version where the issue is resolved.
CVE-2005-3011 can be exploited by local users with access to the system, allowing them to overwrite files.
The impact of CVE-2005-3011 on system security includes the potential for unauthorized file modification, leading to data loss or system compromise.