CVE Database
/

CVE-2005-3785

Back to search

CVE-2005-3785

Published: Nov 23, 2005

Modified: Aug 7, 2024

PUBLISHED

Description

Second-order symlink vulnerability in eix-sync.in in Ebuild IndeX (eix) before 0.5.0_pre2 allows local users to overwrite arbitrary files via a symlink attack on the exi.X.sync temporary file, which is processed by the diff-eix program.

VendorProductVersions

n/a

n/a

affected
n/a

References

17699
third-party-advisory
x_refsource_SECUNIA
GLSA-200511-19
vendor-advisory
x_refsource_GENTOO
ADV-2005-2539
vdb-entry
x_refsource_VUPEN
15541
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now