CVE-2006-5072: Medium severity Mono Mono vulnerability
The System.CodeDom.Compiler classes in Novell Mono create temporary files with insecure permissions, which allows local users to overwrite arbitrary files or execute arbitrary code via a symlink attack.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-5072?
CVE-2006-5072 is considered a moderate severity vulnerability due to the potential for local users to exploit insecure file permissions.
How do I fix CVE-2006-5072?
To fix CVE-2006-5072, ensure that the Mono installation creates temporary files with secure permissions and apply any appropriate updates provided by the vendor.
What systems are affected by CVE-2006-5072?
CVE-2006-5072 affects Mono version 1.0 and 2.0 installations.
What kind of attack can be performed using CVE-2006-5072?
An attacker can perform a symlink attack to overwrite files or execute unauthorized code due to insecure temporary file permissions.
Is CVE-2006-5072 exploitable remotely?
CVE-2006-5072 is not directly exploitable remotely as it requires local access to the system to carry out the attack.