Back to search
CVE-2005-3785
Published: Nov 23, 2005
Modified: Aug 7, 2024
PUBLISHED
Description
Second-order symlink vulnerability in eix-sync.in in Ebuild IndeX (eix) before 0.5.0_pre2 allows local users to overwrite arbitrary files via a symlink attack on the exi.X.sync temporary file, which is processed by the diff-eix program.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
17699
third-party-advisory
x_refsource_SECUNIA
GLSA-200511-19
vendor-advisory
x_refsource_GENTOO
ADV-2005-2539
vdb-entry
x_refsource_VUPEN
15541
vdb-entry
x_refsource_BID
http://bugs.gentoo.org/show_bug.cgi?id=112061
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now