4.6
CVSSv2

CVE-2005-2693

Published: 26/08/2005 Updated: 11/10/2017
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

cvsbug in CVS 1.12.12 and previous versions creates temporary files insecurely, which allows local users to overwrite arbitrary files and execute arbitrary code via a symlink attack.

Vulnerable Product Search on Vulmon Subscribe to Product

cvs cvs 1.12.12

Vendor Advisories

Synopsis cvs security update Type/Severity Security Advisory: Low Topic An updated cvs package that fixes a security bug is now availableThis update has been rated as having low security impact by theRed Hat Security Response Team Description CVS (Concurrent Version System) is a version c ...
Marcus Meissner discovered that the cvsbug program from CVS, which serves the popular Concurrent Versions System, uses temporary files in an insecure fashion For the old stable distribution (woody) this problem has been fixed in version 1111p1debian-13 In the stable distribution (sarge) the cvs package does not expose the cvsbug program anymore ...
Marcus Meissner discovered that the cvsbug program from gcvs, the Graphical frontend for CVS, which serves the popular Concurrent Versions System, uses temporary files in an insecure fashion For the old stable distribution (woody) this problem has been fixed in version 10a7-2woody1 For the stable distribution (sarge) this problem has been fixed ...