CVE-2005-4772: Medium severity SUSE Suse Sled Beagle vulnerability

Published Dec 31, 2005
·
Updated

liby2util in Yet another Setup Tool (YaST) in SUSE Linux before 20051007 preserves permissions and ownerships when copying a remote repository, which might allow local users to read or modify sensitive files, possibly giving local users the ability to exploit CVE-2005-3013.

Affected Software

25 affected components
SUSE Suse Sled Beagle=10.0
SUSE Suse Linux Standard Server=8.0
SUSE Suse Linux Openexchange Server=4.0
SUSE Suse Linux School Server=gold
SUSE SuSE Linux=9.0
SUSE SuSE Linux=8.0
SUSE SuSE Linux=9.0
SUSE SuSE Linux=9.1
SUSE SuSE Linux=9.0
SUSE SuSE Linux=10.0
SUSE SuSE Linux=9.3
SUSE SuSE Linux=8
SUSE SuSE Linux=9.3
SUSE SuSE Linux=1.0
SUSE SuSE Linux=9.0
SUSE SuSE Linux=9.2
SUSE SuSE Linux=10.0
SUSE SuSE Linux=8.2
SUSE SuSE Linux=9.0
SUSE SuSE Linux=9.1
SUSE SuSE Linux=9.3
SUSE SuSE Linux=9.2
SUSE SuSE Linux=9.2
SUSE SuSE Linux=9.1
SUSE SuSE Linux=8.2

Event History

Dec 31, 2005
CVE Published
05:00 AM
Apr 7, 2006
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description

Frequently Asked Questions

1

What is the severity of CVE-2005-4772?

CVE-2005-4772 has a moderate severity level due to the potential unauthorized access to sensitive files by local users.

2

How do I fix CVE-2005-4772?

To fix CVE-2005-4772, update to the latest version of the affected SUSE Linux distributions or apply the relevant security patches.

3

What are the affected software versions for CVE-2005-4772?

CVE-2005-4772 affects various versions of SUSE Linux, including 10.0, 9.0, 9.1, 9.2, 9.3, 8.0, 8.2, and others.

4

Can CVE-2005-4772 be exploited remotely?

No, CVE-2005-4772 requires local access to the system for exploitation.

5

What type of vulnerability is CVE-2005-4772?

CVE-2005-4772 is classified as a local file inclusion vulnerability due to improper file permission handling.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203