CVE-2005-3885: Low severity Inkscape Inkscape vulnerability
The ps2epsi extension shell script (ps2epsi.sh) in Inkscape before 0.41 allows local users to overwrite arbitrary files via a symlink attack on the tmpepsifile.epsi temporary file.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-3885?
CVE-2005-3885 is considered a moderate severity vulnerability due to the potential for local users to overwrite arbitrary files.
How do I fix CVE-2005-3885?
To fix CVE-2005-3885, upgrade Inkscape to version 0.41 or later to mitigate the symlink attack risk.
Who is affected by CVE-2005-3885?
CVE-2005-3885 affects local users of Inkscape versions prior to 0.41 on systems where they have access to execute the ps2epsi script.
What is a symlink attack in the context of CVE-2005-3885?
A symlink attack in CVE-2005-3885 involves creating a symbolic link to the temporary file used by the ps2epsi script, allowing unauthorized file overwrites.
Is CVE-2005-3885 still a concern for current Inkscape users?
CVE-2005-3885 is not a concern for users of Inkscape version 0.41 and newer, as the vulnerability has been addressed.