Back to search
CVE-2005-4534
Published: Dec 28, 2005
Modified: Aug 7, 2024
PUBLISHED
Description
The shadow database feature (syncshadowdb) in Bugzilla 2.9 through 2.16.10 allows local users to overwrite arbitrary files via a symlink attack on temporary files.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
DSA-1208
vendor-advisory
x_refsource_DEBIAN
302
third-party-advisory
x_refsource_SREASON
18218
third-party-advisory
x_refsource_SECUNIA
16061
vdb-entry
x_refsource_BID
20051228 [BUGZILLA] Security advisory for Bugzilla < 2.16.11
mailing-list
x_refsource_BUGTRAQ
22826
third-party-advisory
x_refsource_SECUNIA
https://bugzilla.mozilla.org/show_bug.cgi?id=305353
x_refsource_CONFIRM
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=329387
x_refsource_MISC
bugzilla-syncshadowdb-symlink(23863)
vdb-entry
x_refsource_XF
1015411
vdb-entry
x_refsource_SECTRACK
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now