2.1
CVSSv2

CVE-2004-0996

Published: 10/01/2005 Updated: 11/07/2017
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 220
Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

main.c in cscope 15-4 and 15-5 creates temporary files with predictable filenames, which allows local users to overwrite arbitrary files via a symlink attack.

Vulnerable Product Search on Vulmon Subscribe to Product

cscope cscope 15.3

cscope cscope 15.4

cscope cscope 15.5

cscope cscope 13.0

cscope cscope 15.1

debian debian linux 3.0

sco unixware 7.1.1

sco unixware 7.1.3

gentoo linux

sco unixware 7.1.4

Vendor Advisories

A vulnerability has been discovered in cscope, a program to interactively examine C source code, which may allow local users to overwrite files via a symlink attack For the stable distribution (woody) this problem has been fixed in version 153-1woody2 For the unstable distribution (sid) this problem has been fixed in version 155-1 We recommend ...

Exploits

source: wwwsecurityfocuscom/bid/11697/info Cscope creates temporary files in an insecure way A design error causes the application to fail to verify the presence of a file before writing to it During execution, the utility reportedly creates temporary files in the system's temporary directory, '/tmp', with predictable names This all ...
source: wwwsecurityfocuscom/bid/11697/info Cscope creates temporary files in an insecure way A design error causes the application to fail to verify the presence of a file before writing to it During execution, the utility reportedly creates temporary files in the system's temporary directory, '/tmp', with predictable names This allo ...