Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2005-2991

Опубликовано: 09 нояб. 2021
Источник: redhat
CVSS3: 5
EPSS Низкий

Описание

ncompress 4.2.4 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files using (1) zdiff or (2) zcmp, a different vulnerability than CVE-2004-0970.

Отчет

Not vulnerable. This issue did not affect the ncompress packages as distributed with Red Hat Enterprise Linux 2.1, 3, or 4.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ncompressNot affected
Red Hat Enterprise Linux 7ncompressNot affected
Red Hat Enterprise Linux 8ncompressNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-59
https://bugzilla.redhat.com/show_bug.cgi?id=2023347ncompress: insecure tmp file handling may lead to file overwrite

EPSS

Процентиль: 27%
0.00092
Низкий

5 Medium

CVSS3

Связанные уязвимости

ubuntu
почти 20 лет назад

ncompress 4.2.4 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files using (1) zdiff or (2) zcmp, a different vulnerability than CVE-2004-0970.

nvd
почти 20 лет назад

ncompress 4.2.4 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files using (1) zdiff or (2) zcmp, a different vulnerability than CVE-2004-0970.

debian
почти 20 лет назад

ncompress 4.2.4 and earlier allows local users to overwrite arbitrary ...

github
больше 3 лет назад

ncompress 4.2.4 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files using (1) zdiff or (2) zcmp, a different vulnerability than CVE-2004-0970.

EPSS

Процентиль: 27%
0.00092
Низкий

5 Medium

CVSS3