First published: Fri Nov 18 2005(Updated: )
GNU Gnump3d before 2.9.8 allows local users to modify or delete arbitrary files via a symlink attack on the index.lok temporary file.
Credit: security@debian.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU Gnump3d | =2.9 | |
GNU Gnump3d | =2.9.5 | |
GNU Gnump3d | =2.9.2 | |
GNU Gnump3d | =2.9.4 | |
GNU Gnump3d | =2.9.3 | |
GNU Gnump3d | <=2.9.7 | |
GNU Gnump3d | =2.9.6 | |
GNU Gnump3d | =2.9.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-3349 has a medium severity rating due to its potential for local users to perform unauthorized file operations.
To fix CVE-2005-3349, upgrade to GNU Gnump3d version 2.9.8 or later.
CVE-2005-3349 affects all versions of GNU Gnump3d prior to 2.9.8.
A symlink attack allows a local user to create a symbolic link to modify or delete files by exploiting the temporary index.lok file.
CVE-2005-3349 cannot be exploited remotely as it requires local user access to the affected system.