CVE-2005-3349: Low severity GNU gnump3d vulnerability
Published Nov 18, 2005
·Updated
GNU Gnump3d before 2.9.8 allows local users to modify or delete arbitrary files via a symlink attack on the index.lok temporary file.
Affected Software
8 affected components
GNU gnump3d<=2.9.7
GNU gnump3d=2.9
GNU gnump3d=2.9.1
GNU gnump3d=2.9.2
GNU gnump3d=2.9.3
GNU gnump3d=2.9.4
GNU gnump3d=2.9.5
GNU gnump3d=2.9.6
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Nov 18, 2005
CVE Published
10:03 PM
Nov 19, 2005
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-3349?
CVE-2005-3349 has a medium severity rating due to its potential for local users to perform unauthorized file operations.
2
How do I fix CVE-2005-3349?
To fix CVE-2005-3349, upgrade to GNU Gnump3d version 2.9.8 or later.
3
What types of systems are affected by CVE-2005-3349?
CVE-2005-3349 affects all versions of GNU Gnump3d prior to 2.9.8.
4
What is a symlink attack in the context of CVE-2005-3349?
A symlink attack allows a local user to create a symbolic link to modify or delete files by exploiting the temporary index.lok file.
5
Can CVE-2005-3349 be exploited remotely?
CVE-2005-3349 cannot be exploited remotely as it requires local user access to the affected system.