6.2
CVSSv2

CVE-2006-5072

Published: 10/10/2006 Updated: 20/07/2017
CVSS v2 Base Score: 6.2 | Impact Score: 10 | Exploitability Score: 1.9
VMScore: 552
Vector: AV:L/AC:H/Au:N/C:C/I:C/A:C

Vulnerability Summary

The System.CodeDom.Compiler classes in Novell Mono create temporary files with insecure permissions, which allows local users to overwrite arbitrary files or execute arbitrary code via a symlink attack.

Vulnerable Product Search on Vulmon Subscribe to Product

mono mono 1.0

mono mono 2.0

Vendor Advisories

Sebastian Krahmer of the SuSE security team discovered that the SystemCodeDomCompiler classes used temporary files in an insecure way This could allow a symbolic link attack to create or overwrite arbitrary files with the privileges of the user invoking the program Under some circumstances, a local attacker could also exploit this to inject arb ...