CVE-2005-1880

everybuddy 0.4.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file created by a system call to wget.
References
Link Resource
http://bugs.gentoo.org/show_bug.cgi?id=94473 Exploit Issue Tracking
http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034422.html Not Applicable Vendor Advisory
http://securitytracker.com/id?1014110 Broken Link Third Party Advisory VDB Entry Vendor Advisory
http://www.securityfocus.com/bid/13865 Broken Link Third Party Advisory VDB Entry Vendor Advisory
http://www.zataz.net/adviso/everybuddy-06062005.txt Broken Link Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:everybuddy:everybuddy:*:*:*:*:*:*:*:*

History

26 Jan 2024, 17:00

Type Values Removed Values Added
CPE cpe:2.3:a:everybuddy:everybuddy:0.4.3:*:*:*:*:*:*:* cpe:2.3:a:everybuddy:everybuddy:*:*:*:*:*:*:*:*
CWE NVD-CWE-Other CWE-59
CVSS v2 : 2.1
v3 : unknown
v2 : 2.1
v3 : 5.5
References (SECTRACK) http://securitytracker.com/id?1014110 - Vendor Advisory (SECTRACK) http://securitytracker.com/id?1014110 - Broken Link, Third Party Advisory, VDB Entry, Vendor Advisory
References (MISC) http://www.zataz.net/adviso/everybuddy-06062005.txt - Vendor Advisory (MISC) http://www.zataz.net/adviso/everybuddy-06062005.txt - Broken Link, Vendor Advisory
References (MISC) http://bugs.gentoo.org/show_bug.cgi?id=94473 - Vendor Advisory (MISC) http://bugs.gentoo.org/show_bug.cgi?id=94473 - Exploit, Issue Tracking
References (FULLDISC) http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034422.html - Vendor Advisory (FULLDISC) http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034422.html - Not Applicable, Vendor Advisory
References (BID) http://www.securityfocus.com/bid/13865 - Vendor Advisory (BID) http://www.securityfocus.com/bid/13865 - Broken Link, Third Party Advisory, VDB Entry, Vendor Advisory

Information

Published : 2005-06-06 04:00

Updated : 2024-02-28 10:42


NVD link : CVE-2005-1880

Mitre link : CVE-2005-1880

CVE.ORG link : CVE-2005-1880


JSON object : View

Products Affected

everybuddy

  • everybuddy
CWE
CWE-59

Improper Link Resolution Before File Access ('Link Following')