First published: Sat Dec 31 2005(Updated: )
imake in NetBSD before 2.0.3, NetBSD-current before 12 September 2005, certain versions of X.Org, and certain versions of XFree86 allows local users to overwrite arbitrary files via a symlink attack on the temporary file for the file.0 target, which is used for a pre-formatted manual page.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
NetBSD current | =1.6 | |
NetBSD current | =2.0.2 | |
NetBSD current | =1.6.1 | |
NetBSD current | =1.6.2 | |
NetBSD current | =1.6-beta | |
NetBSD current | =2.0.1 | |
NetBSD current | =2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-4691 has a medium severity rating due to the potential for local users to overwrite arbitrary files.
To fix CVE-2005-4691, upgrade to the latest version of NetBSD that addresses this vulnerability.
CVE-2005-4691 affects NetBSD versions before 2.0.3 and certain older versions of X.Org and XFree86.
CVE-2005-4691 is exploited through a symlink attack on the temporary file used for pre-formatted manual pages.
Yes, local users on affected systems can potentially use CVE-2005-4691 to overwrite files.