1.2
CVSSv2

CVE-2006-1695

Published: 11/04/2006 Updated: 20/07/2017
CVSS v2 Base Score: 1.2 | Impact Score: 2.9 | Exploitability Score: 1.9
VMScore: 107
Vector: AV:L/AC:H/Au:N/C:N/I:P/A:N

Vulnerability Summary

The fbgs script in the fbi package 2.01-1.4, when the TMPDIR environment variable is not defined, allows local users to overwrite arbitrary files via a symlink attack on temporary files in /var/tmp/fbps-[PID].

Vulnerable Product Search on Vulmon Subscribe to Product

fbida fbida 2.01

fbida fbida 2.02

fbida fbida 2.03

Vendor Advisories

Debian Bug report logs - #361370 fbgs: uses insecure tempfiles Package: fbi; Maintainer for fbi is Moritz Muehlenhoff <jmm@debianorg>; Source for fbi is src:fbi (PTS, buildd, popcon) Reported by: Jan Braun <janbraun@gmxnet> Date: Sat, 8 Apr 2006 10:03:07 UTC Severity: important Tags: patch, security Found in ver ...
Jan Braun discovered that the fbgs script of fbi, an image viewer for the framebuffer environment, creates an directory in a predictable manner, which allows denial of service through symlink attacks For the old stable distribution (woody) this problem has been fixed in version 123woody1 For the stable distribution (sarge) this problem has been ...