VulnerabilityModified
CVE-2005-2693
cvsbug in CVS 1.12.12 and earlier creates temporary files insecurely, which allows local users to overwrite arbitrary files and execute arbitrary code via a symlink attack.
MEDIUM 4.6EPSS 0.44%
Does this matter?
Lower severity and a low EPSS score (0.44%). Track it; it rarely justifies an emergency change on its own.
Description
cvsbug in CVS 1.12.12 and earlier creates temporary files insecurely, which allows local users to overwrite arbitrary files and execute arbitrary code via a symlink attack.
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 0.44% probability · 37th percentile
- CISA KEV
- Not listed
- Affected
- cvs/cvs
- Source
- secalert@redhat.com
References
- ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:20.cvsbug.asc
- http://secunia.com/advisories/16765
- http://securitytracker.com/id?1014857
- http://www.debian.org/security/2005/dsa-802
- http://www.debian.org/security/2005/dsa-806
- http://www.redhat.com/support/errata/RHSA-2005-756.html
- http://www.vupen.com/english/advisories/2005/1667
- https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=166366Patch
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10835
- ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-05:20.cvsbug.asc
- http://secunia.com/advisories/16765
- http://securitytracker.com/id?1014857
- http://www.debian.org/security/2005/dsa-802
- http://www.debian.org/security/2005/dsa-806
- http://www.redhat.com/support/errata/RHSA-2005-756.html
- http://www.vupen.com/english/advisories/2005/1667
- https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=166366Patch
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10835
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.