7.2
CVSSv2

CVE-2005-0610

Published: 12/04/2005 Updated: 05/09/2008
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Multiple symlink vulnerabilities in portupgrade prior to 20041226_2 in FreeBSD allow local users to (1) overwrite arbitrary files and possibly replace packages to execute arbitrary code via pkg_fetch, (2) overwrite arbitrary files via temporary files when portupgrade upgrades a port or package, or (3) create arbitrary zero-byte files via the pkgdb.fixme temporary file.

Vulnerable Product Search on Vulmon Subscribe to Product

freebsd freebsd 4.10

freebsd freebsd 4.11

freebsd freebsd 4.5

freebsd freebsd 4.8

freebsd freebsd 4.9

freebsd freebsd 5.3

freebsd freebsd 4.1

freebsd freebsd 4.1.1

freebsd freebsd 4.2

freebsd freebsd 4.3

freebsd freebsd 4.4

freebsd freebsd 4.6.2

freebsd freebsd 4.6

freebsd freebsd 4.7

freebsd freebsd 5.0

freebsd freebsd 5.1

freebsd freebsd 5.2.1

freebsd freebsd 5.4

freebsd freebsd 4.0

freebsd freebsd 5.2