First published: Wed Oct 05 2005(Updated: )
The (1) cfmailfilter and (2) cfcron.in files for cfengine 1.6.5 allow local users to overwrite arbitrary files via a symlink attack on temporary files, a different vulnerability than CVE-2005-2960.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
CFEngine | =1.6.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-3137 has a medium severity rating due to its potential for local file overwriting.
To fix CVE-2005-3137, you should upgrade to a version of CFEngine that is not affected by this vulnerability.
The CVE-2005-3137 vulnerability specifically affects GNU CFEngine version 1.6.5.
CVE-2005-3137 involves a symlink attack that allows local users to overwrite arbitrary files.
CVE-2005-3137 can be exploited by local users on systems running the affected version of CFEngine.