CVE-2005-4536: Low severity Debian Libmail-audit-perl vulnerability
Mail::Audit module in libmail-audit-perl 2.1-5, when logging is enabled without a default log file specified, uses predictable log filenames, which allows local users to overwrite arbitrary files via a symlink attack on the [PID]-audit.log temporary file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2005-4536?
CVE-2005-4536 is considered a medium severity vulnerability due to its potential for local file system manipulation.
How do I fix CVE-2005-4536?
To fix CVE-2005-4536, ensure to configure a default log file for Mail::Audit and avoid using predictable log filenames.
Who is affected by CVE-2005-4536?
CVE-2005-4536 affects users of the Mail::Audit module in libmail-audit-perl version 2.1-5 on Debian systems.
What type of attack is associated with CVE-2005-4536?
CVE-2005-4536 is associated with a symlink attack that allows local users to overwrite arbitrary log files.
What are the consequences of CVE-2005-4536?
The consequences of CVE-2005-4536 include potential data loss and unauthorized access to sensitive information by overwriting log files.