Описание
The ispell_op function in ee on FreeBSD 4.10 to 6.0 uses predictable filenames and does not confirm which file is being written, which allows local users to overwrite arbitrary files via a symlink attack when ee invokes ispell.
| Релиз | Статус | Примечание |
|---|---|---|
| dapper | released | 1:1.4.2-5 |
| devel | released | 1:1.4.2-5 |
| edgy | released | 1:1.4.2-5 |
| feisty | released | 1:1.4.2-5 |
| gutsy | released | 1:1.4.2-5 |
| upstream | needs-triage |
Показывать по
Ссылки на источники
EPSS
2.1 Low
CVSS2
Связанные уязвимости
The ispell_op function in ee on FreeBSD 4.10 to 6.0 uses predictable filenames and does not confirm which file is being written, which allows local users to overwrite arbitrary files via a symlink attack when ee invokes ispell.
The ispell_op function in ee on FreeBSD 4.10 to 6.0 uses predictable f ...
The ispell_op function in ee on FreeBSD 4.10 to 6.0 uses predictable filenames and does not confirm which file is being written, which allows local users to overwrite arbitrary files via a symlink attack when ee invokes ispell.
EPSS
2.1 Low
CVSS2