5
CVSSv2

CVE-2005-2918

Published: 15/09/2005 Updated: 18/10/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

The open_cmd_tube function in mount.c for gtkdiskfree 1.9.3 and previous versions allows local users to overwrite arbitrary files via a symlink attack on the gtkdiskfree temporary file.

Vulnerable Product Search on Vulmon Subscribe to Product

gtkdiskfree gtkdiskfree

Vendor Advisories

Eric Romang discovered that gtkdiskfree, a GNOME program that shows free and used space on filesystems, creates a temporary file in an insecure fashion The old stable distribution (woody) does not contain the gtkdiskfree package For the stable distribution (sarge) this problem has been fixed in version 193-4sarge1 For the unstable distribution ...