1.2
CVSSv2

CVE-2005-3342

Published: 31/12/2005 Updated: 08/03/2011
CVSS v2 Base Score: 1.2 | Impact Score: 2.9 | Exploitability Score: 1.9
VMScore: 107
Vector: AV:L/AC:H/Au:N/C:N/I:P/A:N

Vulnerability Summary

noweb 2.10c and previous versions allows local users to overwrite arbitrary files via symlink attacks on temporary files in (1) lib/toascii.nw and (2) shell/roff.mm.

Vulnerable Product Search on Vulmon Subscribe to Product

norman ramsey noweb 2.10c

norman ramsey noweb 2.9a

Vendor Advisories

Javier Fern�ndez-Sanguino Pe�a discovered that noweb scripts created temporary files in an insecure way This could allow a symlink attack to create or overwrite arbitrary files with the privileges of the user running noweb ...