2.1
CVSSv2

CVE-2005-2240

Published: 12/07/2005 Updated: 05/09/2008
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

xpvm.tcl in xpvm 1.2.5 allows local users to overwrite arbitrary files via a symlink attack on the xpvm.trace.$user temporary file.

Vulnerable Product Search on Vulmon Subscribe to Product

xpvm xpvm 1.2.5

Vendor Advisories

Eric Romang discovered that xpvm, a graphical console and monitor for PVM, creates a temporary file that allows local attackers to create or overwrite arbitrary files with the privileges of the user running xpvm For the old stable distribution (woody) this problem has been fixed in version 125-72woody1 For the stable distribution (sarge) this ...