CVE-2005-3123: Medium severity GNU gnump3d vulnerability
Published Oct 30, 2005
·Updated
Directory traversal vulnerability in GNUMP3D before 2.9.6 allows remote attackers to read arbitrary files via crafted sequences such as "/.//..//////././", which is collapsed into "/.././" after ".." and "//" sequences are removed.
Affected Software
6 affected components
GNU gnump3d=2.9
GNU gnump3d=2.9.1
GNU gnump3d=2.9.2
GNU gnump3d=2.9.3
GNU gnump3d=2.9.4
GNU gnump3d=2.9.5
Remediation
Patch Available
Patch Available
Patch Available
Event History
Oct 30, 2005
CVE Published
08:02 PM
Oct 31, 2005
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-3123?
CVE-2005-3123 has a medium severity rating due to its potential for unauthorized file access.
2
How do I fix CVE-2005-3123?
To fix CVE-2005-3123, upgrade GNUMP3D to version 2.9.6 or later, which addresses the directory traversal vulnerability.
3
Who is affected by CVE-2005-3123?
CVE-2005-3123 affects all versions of GNUMP3D prior to 2.9.6.
4
What type of vulnerability is CVE-2005-3123?
CVE-2005-3123 is classified as a directory traversal vulnerability.
5
Can CVE-2005-3123 lead to data exposure?
Yes, CVE-2005-3123 can allow remote attackers to read arbitrary files, potentially leading to data exposure.