CVE-2005-3137: Low severity gnu cfengine vulnerability
Published Oct 5, 2005
·Updated
The (1) cfmailfilter and (2) cfcron.in files for cfengine 1.6.5 allow local users to overwrite arbitrary files via a symlink attack on temporary files, a different vulnerability than CVE-2005-2960.
Affected Software
1 affected component
GNU CFEngine=1.6.5
Remediation
Patch Available
Patch Available
Event History
Oct 5, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-3137?
CVE-2005-3137 has a medium severity rating due to its potential for local file overwriting.
2
How do I fix CVE-2005-3137?
To fix CVE-2005-3137, you should upgrade to a version of CFEngine that is not affected by this vulnerability.
3
What systems are affected by CVE-2005-3137?
The CVE-2005-3137 vulnerability specifically affects GNU CFEngine version 1.6.5.
4
What type of attack does CVE-2005-3137 involve?
CVE-2005-3137 involves a symlink attack that allows local users to overwrite arbitrary files.
5
Who can exploit CVE-2005-3137?
CVE-2005-3137 can be exploited by local users on systems running the affected version of CFEngine.