4.6
CVSSv2

CVE-2005-4802

Published: 31/12/2005 Updated: 18/10/2016
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Flexbackup 1.2.1 and previous versions allows local users to overwrite files and execute code via a symlink attack on temporary files. NOTE: the raw source referenced an incorrect candidate number; this is the correct number to use.

Vulnerable Product Search on Vulmon Subscribe to Product

flexbackup flexbackup

Vendor Advisories

Eric Romang discovered that the flexbackup backup tool creates temporary files in an insecure manner, which allows denial of service through a symlink attack For the stable distribution (sarge) this problem has been fixed in version 121-2sarge1 For the upcoming stable distribution (etch) this problem has been fixed in version 121-3 For the u ...