CVE-2005-3785: Medium severity Gentoo Linux Eix vulnerability
Published Nov 23, 2005
·Updated
Second-order symlink vulnerability in eix-sync.in in Ebuild IndeX (eix) before 0.5.0pre2 allows local users to overwrite arbitrary files via a symlink attack on the exi.X.sync temporary file, which is processed by the diff-eix program.
Affected Software
1 affected component
Gentoo Linux Eix<=0.3
Remediation
Patch Available
Event History
Nov 23, 2005
CVE Published
11:03 PM
Nov 24, 2005
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-3785?
CVE-2005-3785 has a medium severity rating due to the potential for local users to exploit the symlink vulnerability.
2
How do I fix CVE-2005-3785?
To fix CVE-2005-3785, upgrade to Ebuild IndeX (eix) version 0.5.0_pre2 or later.
3
Which systems are affected by CVE-2005-3785?
CVE-2005-3785 affects Gentoo Linux Eix versions up to 0.3.
4
What type of vulnerability is CVE-2005-3785?
CVE-2005-3785 is classified as a second-order symlink vulnerability.
5
Can CVE-2005-3785 be exploited remotely?
CVE-2005-3785 cannot be exploited remotely as it requires local access to the system.