CVE-2006-6939: Medium severity GNU ed vulnerability
Published Jan 17, 2007
·Updated
GNU ed before 0.3 allows local users to overwrite arbitrary files via a symlink attack on temporary files, possibly in the opensbuf function.
Affected Software
1 affected component
GNU ed<=0.2
Event History
Jan 17, 2007
CVE Published
12:28 AM
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-6939?
CVE-2006-6939 has a moderate severity level as it allows local users to perform a symlink attack.
2
How do I fix CVE-2006-6939?
To fix CVE-2006-6939, users should upgrade to GNU ed version 0.3 or later.
3
Who is affected by CVE-2006-6939?
Local users of GNU ed versions prior to 0.3 are affected by CVE-2006-6939.
4
What type of attack is associated with CVE-2006-6939?
CVE-2006-6939 is associated with a symlink attack that can lead to file overwrites.
5
What is the impact of exploiting CVE-2006-6939?
Exploiting CVE-2006-6939 can allow a local user to overwrite arbitrary files on the system.