First published: Tue Nov 29 2005(Updated: )
The ps2epsi extension shell script (ps2epsi.sh) in Inkscape before 0.41 allows local users to overwrite arbitrary files via a symlink attack on the tmpepsifile.epsi temporary file.
Credit: security@debian.org
Affected Software | Affected Version | How to fix |
---|---|---|
Inkscape | =0.41 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-3885 is considered a moderate severity vulnerability due to the potential for local users to overwrite arbitrary files.
To fix CVE-2005-3885, upgrade Inkscape to version 0.41 or later to mitigate the symlink attack risk.
CVE-2005-3885 affects local users of Inkscape versions prior to 0.41 on systems where they have access to execute the ps2epsi script.
A symlink attack in CVE-2005-3885 involves creating a symbolic link to the temporary file used by the ps2epsi script, allowing unauthorized file overwrites.
CVE-2005-3885 is not a concern for users of Inkscape version 0.41 and newer, as the vulnerability has been addressed.