2.1
CVSSv2

CVE-2005-3885

Published: 29/11/2005 Updated: 03/10/2018
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

The ps2epsi extension shell script (ps2epsi.sh) in Inkscape prior to 0.41 allows local users to overwrite arbitrary files via a symlink attack on the tmpepsifile.epsi temporary file.

Vulnerable Product Search on Vulmon Subscribe to Product

inkscape inkscape 0.41

Vendor Advisories

Javier Fern�ndez-Sanguino Pe�a discovered that Inkscape’s ps2epsish script, which converts PostScript files to Encapsulated PostScript format, creates a temporary file in an insecure way A local attacker could exploit this with a symlink attack to create or overwrite arbitrary files with the privileges of the user running Inkscape ...
Several vulnerabilities have been discovered in Inkscape, a vector-based drawing program The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2005-3737 Joxean Koret discovered a buffer overflow in the SVG parsing routines that can lead to the execution of arbitrary code CVE-2005-3885 Javier Fernánd ...